
zeek-quasarrat-detector
Zeek detector for QuasarRat

Zeek detector for QuasarRat

A Zeek based AsyncRAT malware detector.

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

The Sigma command line interface based on pySigma

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, Suricata and…

A utility to safely generate malicious network traffic patterns and evaluate controls.

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Threat hunting command system for agentic IDEs

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Simple honeypot for CVE-2024-3400 Palo Alto PAN-OS Command Injection Vulnerability

Detection of Manjusaka C2 framework

Wazuh detection rules for CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite, monitoring web access logs and zimbra.log for…

Real-world patching workflow for CVE-2025-32709. From hotfix install to SIEM alert validation—this repo documents every step with screenshots,…