
sigint-hombre
Dynamically generated Suricata rules from real-time threat feeds

Dynamically generated Suricata rules from real-time threat feeds

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Slides and materials from conference presentations

This repository demonstrates a machine learning pipeline for detecting MITRE ATT&CK techniques from logs and enriching the output using a local LLM.

This repository talks about Zero-Day Exploitation of Atlassian Confluence, it's defense and analysis point of view from a SecOps or Blue Team…

Anti-Virus for K8s. Protect your Applications running on Kubernetes from malicious attacks with pre-registered source code, runtime processes…

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

Real-world patching workflow for CVE-2025-32709. From hotfix install to SIEM alert validation—this repo documents every step with screenshots,…

Data we are receiving from our honeypots about CVE-2021-44228

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.

📡🍓🍍 Detects wireless network attacks performed by KARMA module (fake AP). Starts deauthentication attack (for fake access points)

📡 🍍Detects activities of PineAP module and starts deauthentication attack (for fake access points - WiFi Pineapple Activities Detection)

DNXFIREWALL® and DAD'S NEXT-GEN FIREWALL™, a C/CPython hybrid next generation firewall built on top of Linux and bound to kernel/ netfilter hooks for…

Capturing, analysing and responding to cyber attacks

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".
