
santa
A binary and file access authorization system for macOS.

A binary and file access authorization system for macOS.

A simple binary wrapper for DNS canarytokens.

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

🐍 High-performance, multi-threaded YARA & IOC scanner

Labtainers: A Docker-based cyber lab framework

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

Windows Analysis and Research Toolkit

Linux Kernel Runtime Integrity with eBPF

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…


A Zeek ELF File Analyzer

CVE-2025-6554

An eBPF program to detect attacks on CVE-2022-0847

Zeek plugin to detect and decrypt XOR-encrypted EXEs

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Redis UAF RCE PoC collection for CVE-2026-23479: safe version checker, exploit module, GDB-assisted PoC, and Sigma detection rules for authorized…

Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write