
Spip-Go
Spip network sensor written in Go

Spip network sensor written in Go

Github mirror of official Kismet repository

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Runtime Application Self Protection for Python web servers, serverless functions and MCP servers, detecting attacks, prompt injection and data leaks…

Mapping Corelight or Zeek data to Elastic Common Schema logs

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

JA4+ is a suite of network fingerprinting standards

This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

DShield Sensor Log Collection with ELK

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

teamcity teamcity-CVE-2026-63077 exploitation pcap

NFStream: a Flexible Network Data Analysis Framework.

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

Sigma detection rules for AI agent security monitoring