
Exploitarium-Detections
KQL detection rules for Microsoft Sentinel and Defender XDR covering the bikini/exploitarium anonymous disclosure — a personal research archive of…

KQL detection rules for Microsoft Sentinel and Defender XDR covering the bikini/exploitarium anonymous disclosure — a personal research archive of…

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

BlackBerry Threat Research & Intelligence

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)


Simple webhook to block exploitation of CVE-2022-0811

A ModSecurity ruleset for detecting potential attacks using CVE-2018-6389

Dockerized honeypot for CVE-2021-44228.

Simple honeypot for CVE-2021-41773 vulnerability

Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

Security research on Erlang/OTP SSH CVE-2025-32433.

CitrixBleed 2 NetScaler honeypot logs


Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.