
ehids-agent
A Linux Host-based Intrusion Detection System based on eBPF.

A Linux Host-based Intrusion Detection System based on eBPF.

The Sigma command line interface based on pySigma

ETW based POC to identify direct and indirect syscalls

Machine Learning based Intrusion Detection Systems are difficult to evaluate due to a shortage of datasets representing accurately network traffic…

XDP Based Lightweight and Fast Firewall

A tool to generate Snort rules based on public IP reputation data

A host based IDS written in C# Targetted at Metasploit

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

A Zeek OpenVPN protocol analyzer, based on Spicy.

A Zeek IPSec protocol analyzer based on Spicy.


A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

A Zeek based AsyncRAT malware detector.

Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health…

A Zeek based STRRAT malware detector.

A Zeek based Agent Tesla malware C2 detector.

A Zeek based Mitre Caldera detector.

A Zeek based Gozi banking malware detector.