
KOOBE-Guard
Linux kernel module using Kprobes to detect and neutralize CVE-2024-1086 heap double-free exploits via temporal gap tracking and active register…

Linux kernel module using Kprobes to detect and neutralize CVE-2024-1086 heap double-free exploits via temporal gap tracking and active register…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

DShield Sensor Log Collection with ELK

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

Signatures and IoCs from public Volexity blog posts.

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

The Sigma command line interface based on pySigma

Rules generated from our investigations.

Docker configuration to quickly setup your own Canarytokens.

Detect Tactics, Techniques & Combat Threats

Documentation and scripts to properly enable Windows event logs.

A repository to release detection rules to the public

Default Detections for EDR

Purpleteam scripts simulation & Detection - trigger events for SOC detections