
Azure-Sentinel
Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Github mirror of official Kismet repository

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

YARA signature and IOC database for my scanners and tools

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…


This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

Rules generated from our investigations.

The Sigma command line interface based on pySigma

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.

TrustedSec Sysinternals Sysmon Community Guide

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.