
falco
Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Small tool to play with IOCs caused by Imageload events

Generates simulated malicious process, file, registry, and DNS events with custom parent/child attributes, letting defenders validate detection rules…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Inspect live Windows system internals: processes, services, network, kernel callbacks, SSDT, and per-process anomalies; detect hooks and rootkits…

A binary and file access authorization system for macOS.

NCC Group research repository with decoding scripts, Yara and Suricata signatures for APT15 (Royal APT) malware, enabling beacon analysis and command…

Automated Network Security with Rust: Detecting and Blocking Port Scanners

A Go library for using zeek broker's websocket API

Zeek package and Suricata rules to detect ICMP ping tunnels associated with the Pingback C2 malware, enabling network defense against covert…

Configures Raspberry Pi to run Corelight Software Sensor for network security monitoring, extracting metadata/alerts and forwarding to Splunk or…

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Azure Sentinel detection lab for MCP attack patterns, providing 5 analytics rules and 7 KQL hunting queries against SSRF token theft, tool poisoning,…

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…

Passive cross-protocol attack detection tool for mobile core networks. Correlates SS7/MAP, Diameter S6a, and GTPv2-C events to detect location…

Rust tool to detect cell site simulators on an orbic mobile hotspot