
shadowd
The Shadow Daemon web application firewall server

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

eBPF-based Security Observability and Runtime Enforcement

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

Security event correlation engine for ELK stack

eBPF-powered runtime security sensor for CI/CD pipelines. Detects supply-chain attacks, logs process ancestry and file access, and provides forensic…

A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

A binary and file access authorization system for macOS.

Galah: An LLM-powered web honeypot.

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

XDP Based Lightweight and Fast Firewall

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

A curated list of resources related to Industrial Control System (ICS) security.

eBPF-based runtime security agent for Kubernetes that detects unknown processes and file changes, enforces pre-registered constraints, and automates…

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…