
osquery
SQL powered operating system instrumentation, monitoring, and analytics.

SQL powered operating system instrumentation, monitoring, and analytics.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

VEDAS-Driven Autonomous Generation + Community Contributions of Suricata & Nuclei Rules for over 13,000 CVEs

GitHub mirror of the Linux Kernel's audit repository

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Labtainers: A Docker-based cyber lab framework

NFStream: a Flexible Network Data Analysis Framework.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Hardened container staging framework with seccomp syscall whitelisting and eBPF telemetry to detect and block container escape and kernel ULP…

Kernel-runtime defense framework for AF_ALG vulnerabilities, featuring eBPF socket tracing, Ansible hardening, and a crypto auditor for drift…

Training-free anomaly detection framework using Shannon Entropy, Fisher Information, and Wasserstein Distance to map system states into geometrically…

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…


Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

Detection framework for CVE-2025-32463 sudo privilege escalation vulnerability. Provides real-time monitoring, forensic analysis, and SIEM…

Framework for implementing Network Intrusion Detection Systems (NIDS) aimed at identifying anomalies in network flows using Federated Learning models.