
libpcap
System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Github mirror of official Kismet repository

Spip network sensor written in Go

Threat hunting command system for agentic IDEs

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Training-free anomaly detection framework using Shannon Entropy, Fisher Information, and Wasserstein Distance to map system states into geometrically…

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)

Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

Honeynet Project generic authenticated datafeed protocol


A Zeek OpenVPN protocol analyzer plugin.

Multivariate statistical network monitoring sensor that detects anomalies using PCA-based techniques, aggregating lightweight statistics from…