
packetStrider
A network packet forensics tool for SSH

A network packet forensics tool for SSH

Corelight@Home script

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

RPi3+ Network Cracker Setup Tool

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Ability to detect suspicious activity such as (WEP/WPA/WPS) attack by sniffing the air for wireless packets.


A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

Detection rule validation

Monitors Asterisk authentication logs and automatically bans IPs with repeated failed login attempts using iptables, with configurable thresholds and…

Machine Learning based Intrusion Detection Systems are difficult to evaluate due to a shortage of datasets representing accurately network traffic…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…