
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Spip network sensor written in Go

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

A repository of sysmon configuration modules

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Detect Tactics, Techniques & Combat Threats

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Mapping Corelight or Zeek data to Elastic Common Schema logs

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Threat hunting command system for agentic IDEs

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation

Defensive detection package for CVE-2026-31431 (Linux kernel AF_ALG LPE). Sigma, Falco, auditd, KQL, and EQL rules mapped to MITRE ATT&CK…

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228

Curated repository of detection information and validation guidance for identifying malicious activity in enterprise environments.

Sigma Rule for CVE-2025-49666