
galah
Galah: An LLM-powered web honeypot.

Galah: An LLM-powered web honeypot.

OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.

A Linux Host-based Intrusion Detection System based on eBPF.


JA4+ is a suite of network fingerprinting standards

Cyber Security Awareness Framework (CSAF)

Capturing, analysing and responding to cyber attacks

Github mirror of official Kismet repository


Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Primary data pipelines for intrusion detection, security analytics and threat hunting

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Daemon to ban hosts that cause multiple authentication errors

Automate the creation of a lab environment complete with security tooling and logging best practices

Security event correlation engine for ELK stack

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

A Linux Auditd rule set mapped to MITRE's Attack Framework