
osquery
SQL powered operating system instrumentation, monitoring, and analytics.

SQL powered operating system instrumentation, monitoring, and analytics.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

A repository of sysmon configuration modules

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Detect Tactics, Techniques & Combat Threats

Spip network sensor written in Go

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Mapping Corelight or Zeek data to Elastic Common Schema logs

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Threat hunting command system for agentic IDEs

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228

Collection of private Yara rules.

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…