
rayhunter
Rust tool to detect cell site simulators on an orbic mobile hotspot

Rust tool to detect cell site simulators on an orbic mobile hotspot

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

Windows honeypot using ProjFS to project decoy files that trigger Event Log and desktop alerts when accessed, with SMB remote session logging for…

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

Detection and mitigation scripts for CVE-2026-8838, providing vulnerability scanning, configuration auditing, and incident response guidance to…

Rules generated from our investigations.

End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock…

Detection reverse shell and kill it before trying shell.

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)

Demo for detection and mitigation of HTTP/2 Rapid Reset vulnerability (CVE-2023-44487)

Blue Team detection lab created with Terraform and Ansible in Azure.

Linux Kernel Runtime Integrity with eBPF

Advanced detection of port scanning, DoS and malware attacks using Machine Learning techniques

Small tool to play with IOCs caused by Imageload events