
teamcity-CVE-2026-63077-pcap
teamcity teamcity-CVE-2026-63077 exploitation pcap

teamcity teamcity-CVE-2026-63077 exploitation pcap

DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement…

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

CVE-2019-0604: SharePoint RCE detection rules and sample PCAP

CVE-2021-44228 investigation toolkit with Log4j RCE PoC, JNDIExploit payload runner, Snort detection rules, and PCAP analysis for red and blue team…

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

Training-free anomaly detection framework using Shannon Entropy, Fisher Information, and Wasserstein Distance to map system states into geometrically…

Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic

NetworkAssessment: Network Compromise Assessment Tool

Zeek-based network detector for CVE-2022-24497, identifying RPC portmap exploit attempts via real-time traffic analysis and alerting.

Zeek package to detect CVE-2021-1675 (PrintNightmare) by monitoring named pipes and RPC operations for spoolss exploitation attempts.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

Sniffles: Packet Capture Generator for IDS and Regular Expression Evaluation

SQL powered operating system instrumentation, monitoring, and analytics.

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Arkime is an open source, large scale, full packet capturing, indexing, and database system.