

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster


Monitors Asterisk authentication logs and automatically bans IPs with repeated failed login attempts using iptables, with configurable thresholds and…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

A Zeek OpenVPN protocol analyzer, based on Spicy.

A simple binary wrapper for DNS canarytokens.

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

A Zeek IPSec protocol analyzer based on Spicy.

detection for Apache Struts recon and compromise

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Experimental Decoy Broker

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy

Fingerprint SSH clients and servers.

Defensive Windows security application providing compensating controls for CVE-2017-0144 (EternalBlue/MS17-010) through SMB monitoring, attack…

Detects attempts at exploitation of CVE-2022-3602, a remote code execution vulnerability in OpenSSL v 3.0.0 through v.3.0.6

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

Lab for the CVE-2024-27198