


Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral…

A Wordpress Honeypot

A Linux Host-based Intrusion Detection System based on eBPF.

Network traffic sensor

Honeynet Project generic authenticated datafeed protocol

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

Network anomaly detector that monitors raw packets to identify port scanning activity in real time, with flexible sniffing duration controls and live…

Primary data pipelines for intrusion detection, security analytics and threat hunting

Conveigh is a Windows PowerShell LLMNR/NBNS spoofer detection tool

Tools for investigating Log4j CVE-2021-44228

A script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".

TheLightScope

LLMNR/NBNS/mDNS Spoofing Detection Toolkit