
libpcap
System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

Passive wireless network detector, sniffer, and intrusion detection system supporting Wi-Fi, Bluetooth, SDR, and other radio protocols for real-time…

Lightweight low-interaction network honeypot sensor that captures TCP payloads, performs passive TLS/HTTP/SSH fingerprinting, and outputs structured…

Threat hunting command system for agentic IDEs

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

Training-free anomaly detection framework using Shannon Entropy, Fisher Information, and Wasserstein Distance to map system states into geometrically…

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

Multivariate statistical network monitoring sensor that detects anomalies using PCA-based techniques, aggregating lightweight statistics from…

Transparent internet sensor for threat intelligence with a detection rule framework to tag and analyze network packets. Supports custom rules,…

Zeek script that enriches DNS logs with ICANN TLD, domain, and subdomain fields, and marks trusted domains for threat detection.

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

Medium-interaction SSH honeypot that logs brute force attacks and records full attacker shell interactions with a fake filesystem for threat…

Zeek plugin for detecting and parsing OpenVPN traffic (UDP/TCP with TLS), extracting session and TLS handshake metadata for network security…

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Deceptive MySQL honeypot exploiting LOAD DATA LOCAL INFILE to read Windows files from attackers, capturing WeChat ID, phone number, and location data…

Primary data pipelines for intrusion detection, security analytics and threat hunting