
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

SQL powered operating system instrumentation, monitoring, and analytics.

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

GitHub mirror of the Linux Kernel's audit repository

NFStream: a Flexible Network Data Analysis Framework.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Purple Team Exercise Framework

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…


Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

Framework for implementing Network Intrusion Detection Systems (NIDS) aimed at identifying anomalies in network flows using Federated Learning models.

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Detection of Manjusaka C2 framework

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

A Linux Auditd rule set mapped to MITRE's Attack Framework