
kismet
Passive wireless network detector, sniffer, and intrusion detection system supporting Wi-Fi, Bluetooth, SDR, and other radio protocols for real-time…

Passive wireless network detector, sniffer, and intrusion detection system supporting Wi-Fi, Bluetooth, SDR, and other radio protocols for real-time…

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

Threat hunting command system for agentic IDEs

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)

Multivariate statistical network monitoring sensor that detects anomalies using PCA-based techniques, aggregating lightweight statistics from…

Transparent internet sensor for threat intelligence with a detection rule framework to tag and analyze network packets. Supports custom rules,…

Zeek script that enriches DNS logs with ICANN TLD, domain, and subdomain fields, and marks trusted domains for threat detection.

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

Honeynet Project generic authenticated datafeed protocol

Medium-interaction SSH honeypot that logs brute force attacks and records full attacker shell interactions with a fake filesystem for threat…

Zeek plugin for detecting and parsing OpenVPN traffic (UDP/TCP with TLS), extracting session and TLS handshake metadata for network security…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Deceptive MySQL honeypot exploiting LOAD DATA LOCAL INFILE to read Windows files from attackers, capturing WeChat ID, phone number, and location data…

Primary data pipelines for intrusion detection, security analytics and threat hunting

Tools for investigating Log4j CVE-2021-44228

Data we are receiving from our honeypots about CVE-2021-44228