


Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

Mapping Corelight or Zeek data to Elastic Common Schema logs



Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

Fingerprint SSH clients and servers.

A Zeek detector for CVE-2022-24497.


VMWare vmdir missing access control exploit checker

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

Some files for red team/blue team investigations into CVE-2021-44228

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.


Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…