
Malcolm
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Low-interaction honeypot that emulates vulnerable network services to capture malware, shellcode, and exploit attempts, with IPv6 and TLS support.

Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.

Signatures and IoCs from public Volexity blog posts.

Documentation and scripts to properly enable Windows event logs.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Web interface for Suricata ruleset management, threat hunting, and rule tuning with multi-source feed aggregation, transformation, and activity…

Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

This project is a SIEM with SIRP and Threat Intel, all in one.

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Windows Analysis and Research Toolkit

Pulled Pork for Snort and Suricata rule management (from Google code)

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral…

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

psad: Intrusion Detection and Log Analysis with iptables

CVE-2020-16898 (Bad Neighbor) Microsoft Windows TCP/IP Vulnerability Detection Logic and Rule