
cve-2020-0618
CVE-2020-0618 Honeypot

CVE-2020-0618 Honeypot

Softsensor Docker prototype

teamcity teamcity-CVE-2026-63077 exploitation pcap

DShield Sensor Log Collection with ELK

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

This project is a SIEM with SIRP and Threat Intel, all in one.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Spip network sensor written in Go

SOC detection and incident response lab simulating CVE-2024-27198 authentication bypass in JetBrains TeamCity. Includes ELK SIEM, Suricata IDS, Sigma…

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

Detection rules and YARA/KQL signatures for CVE-2025-60787, an unauthenticated RCE in motionEye via config injection, with process execution and file…

Automate the creation of a lab environment complete with security tooling and logging best practices

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

Kubernetes-native CVE-2026-31431 mitigation with automated kernel module blocking, runtime Falco detection rules, and bashible-based node…

Vulnerability Detection and Mitigation Apache ActiveMQ | Security Architectures and Systems Administration - on - Apache ActiveMQ Deserialization…

Detection script for CVE-2026-31431 (Copy Fail) that checks kernel version, patch presence, kernel configs, AF_ALG socket availability, setuid…

Defensive IR playbook and detection package for CVE-2026-31431 (Copy Fail) Linux kernel LPE, including Sigma, auditd, Falco, Wazuh, YARA, eBPF, and…

Research and detection guidance for CVE-2026-31431, an io_uring-based bypass of syscall monitoring. Provides detection rules for Tetragon, Falco, and…