
SSHintel
Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

Sigma rules for detecting Lazarus Group TTPs, covering malicious document execution, PowerShell abuse, scheduled tasks, and credential access,…

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Wazuh detection rules for CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite, monitoring web access logs and zimbra.log for…

An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.

Detection signatures for CVE-2026-41940 and shemas for cPanel logs

Minimal Redis honeypot detecting RediShell (CVE-2025-49844) exploits.

Detection content for CVE-2026-22557 — UniFi Network Application unauthenticated path traversal (CVSS 10.0). Includes YARA, Sigma, KQL, Splunk SPL,…

Curated list of threat detection and hunting resources: detection rules, SIEM and log analysis tools, endpoint/network monitoring, datasets,…

A repository to share publicly available Velociraptor detection content

Centralized log management platform for collecting, indexing, and analyzing streaming logs, with alerting and event correlation for security…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

DShield Sensor Log Collection with ELK


pySigma OpenSearch backend

The Sigma command line interface based on pySigma

Tools for hunting for threats.