
threat-intel
Signatures and IoCs from public Volexity blog posts.

Signatures and IoCs from public Volexity blog posts.

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Pulled Pork for Snort and Suricata rule management (from Google code)

Rules generated from our investigations.

Sigma rules from Joe Security

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

Slides from various conference talks

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Generate bulk YARA rules from YAML input

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

Dynamically generated Suricata rules from real-time threat feeds

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Slides and materials from conference presentations

This repository demonstrates a machine learning pipeline for detecting MITRE ATT&CK techniques from logs and enriching the output using a local LLM.

This repository talks about Zero-Day Exploitation of Atlassian Confluence, it's defense and analysis point of view from a SecOps or Blue Team…