
siem-threat-detection-lab
Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

Fingerprint SSH clients and servers.

A Zeek detector for CVE-2022-24497.


VMWare vmdir missing access control exploit checker

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

Some files for red team/blue team investigations into CVE-2021-44228

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.


Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

Web interface for Suricata ruleset management, threat hunting, and rule tuning with multi-source feed aggregation, transformation, and activity…

Sigma detection rules for AI agent security monitoring

Zeek Plugin that detects CallStranger (CVE-2020-12695) attempts (http://callstranger.com/)