
Malcolm
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

A binary and file access authorization system for macOS.

Open-source network access control (NAC) system with captive portal, 802.1X, BYOD management, wired/wireless enforcement, and IDS/vulnerability…

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…

Rust tool to detect cell site simulators on an orbic mobile hotspot

Passive cross-protocol attack detection tool for mobile core networks. Correlates SS7/MAP, Diameter S6a, and GTPv2-C events to detect location…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

JA4+ is a suite of network fingerprinting standards

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Azure Sentinel detection lab for MCP attack patterns, providing 5 analytics rules and 7 KQL hunting queries against SSRF token theft, tool poisoning,…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Reproducible PoC environment for CVE-2026-29145 Apache Tomcat CLIENT_CERT + OCSP soft-fail bypass, including exploit scripts, mock OCSP responder,…

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

PoC and detection toolkit for CVE-2026-23813, an unauthenticated nginx regex bypass in HPE Aruba AOS-CX exposing the management REST API and hashed…