
CVE-2025-32433-LAB
A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without…

A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without…

eBPF Security Monitoring and Sandboxing Agent Based on Aya

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

Experimental Decoy Broker

Hardened container staging framework with seccomp syscall whitelisting and eBPF telemetry to detect and block container escape and kernel ULP…

Research and detection guidance for CVE-2026-31431, an io_uring-based bypass of syscall monitoring. Provides detection rules for Tetragon, Falco, and…

Defensive IR playbook and detection package for CVE-2026-31431 (Copy Fail) Linux kernel LPE, including Sigma, auditd, Falco, Wazuh, YARA, eBPF, and…

Detection rules and YARA/KQL signatures for CVE-2025-60787, an unauthenticated RCE in motionEye via config injection, with process execution and file…

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

Dockerized honeypot for CVE-2021-44228.

eBPF-based runtime detector for container breakout vulnerabilities in runc and Docker, monitoring syscalls and Docker daemon calls to detect…

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐

eBPF-based runtime security agent for Kubernetes that detects unknown processes and file changes, enforces pre-registered constraints, and automates…

Educational demo of CVE-2024-21626 runc container escape with eBPF-based detection gadget for exploitation attempts.