
pySigma
Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.

A utility to safely generate malicious network traffic patterns and evaluate controls.

Ruby On Rails Application For Network Security Monitoring

Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

A network packet forensics tool for SSH

Suricata rules for network anomaly detection


eBPF-based runtime kernel security monitor detecting exploits and rootkits via control flow integrity (wCFI) and privilege escalation detection (PSD)…

ETW based POC to identify direct and indirect syscalls

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Detect and log CVE-2019-19781 scan and exploitation attempts.

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…


This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Rust-based endpoint security agent with application whitelisting, attack detection, and prevention. Supports multiple platforms with audited…