
KOOBE-Guard
Linux kernel module using Kprobes to detect and neutralize CVE-2024-1086 heap double-free exploits via temporal gap tracking and active register…

Linux kernel module using Kprobes to detect and neutralize CVE-2024-1086 heap double-free exploits via temporal gap tracking and active register…

Automated Network Security with Rust: Detecting and Blocking Port Scanners

A complete Blue Team Cybersecurity Lab featuring pfSense, Suricata, and ELK Stack for network monitoring and threat detection.

A Zeek protocol analyzer for the Facefish rootkit, based on Spicy.

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

Purpleteam scripts simulation & Detection - trigger events for SOC detections

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

📡🍓🍍 Detects wireless network attacks performed by KARMA module (fake AP). Starts deauthentication attack (for fake access points)

Linux Kernel Runtime Integrity with eBPF

GitHub mirror of the Linux Kernel's audit repository

Daemon to ban hosts that cause multiple authentication errors

Interactive GNU/Linux application firewall that filters outbound connections, blocks ads and malware domains, manages system firewall rules via GUI,…

Rust-based endpoint security agent with application whitelisting, attack detection, and prevention. Supports multiple platforms with audited…

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

Docker configuration to quickly setup your own Canarytokens.

A utility to safely generate malicious network traffic patterns and evaluate controls.

DECeption with Evaluative Integrated Validation Engine (DECEIVE): Let an LLM do all the hard honeypot work!

A high interaction SSH honeypot