
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

SQL powered operating system instrumentation, monitoring, and analytics.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

Github mirror of official Kismet repository

Spip network sensor written in Go

Threat hunting command system for agentic IDEs

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…


Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)


Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Honeynet Project generic authenticated datafeed protocol