
GPEWebDefender
Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Sigma detection rules for AI agent security monitoring

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Purple Team Exercise Framework

Deep Learning models for network traffic classification

Zeek package for tracking long connections to report them before they have completed.

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Fingerprint SSH clients and servers.

Different rules to detect if CVE-2021-31166 is being exploited

By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.

A network detection package for CVE-2020-5902, a CVE10.0 vulnerability affecting F5 Networks, Inc BIG-IP devices.

Top DNS Measurement for Bro

📡 🍍Detects activities of PineAP module and starts deauthentication attack (for fake access points - WiFi Pineapple Activities Detection)