
pySigma
Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Windows honeypot using ProjFS to project decoy files that trigger Event Log and desktop alerts when accessed, with SMB remote session logging for…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

Signatures and IoCs from public Volexity blog posts.

Experimental Decoy Broker


The Sigma command line interface based on pySigma

ioc2rpz is a place where threat intelligence meets DNS.

TheLightScope

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write

ML-Based behavioral endpoint detection system for Linux machines

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…


Public repository of Sigma and YARA rules created by Synacktiv