


Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

eBPF-based Security Observability and Runtime Enforcement

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…


Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

Simple webhook to block exploitation of CVE-2022-0811

Labtainers: A Docker-based cyber lab framework

Security event correlation engine for ELK stack

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

Kubernetes-native CVE-2026-31431 mitigation with automated kernel module blocking, runtime Falco detection rules, and bashible-based node…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules

Automate the creation of a lab environment complete with security tooling and logging best practices

A high interaction SSH honeypot