
Intrusion-Alert-Educational-Network-IDS
Lightweight Python-based IDS that monitors network traffic in real-time using Scapy, detecting DoS/DDoS attacks via per-IP request rate analysis with…

Lightweight Python-based IDS that monitors network traffic in real-time using Scapy, detecting DoS/DDoS attacks via per-IP request rate analysis with…

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

A tool to monitor local network traffic for possible security vulnerabilities. Warns user against possible nmap scans, Nikto scans, credentials sent…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

TheLightScope

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

🍓📡🍍Monitor illegal wireless network activities. (Fake Access Points), (WiFi Threats: KARMA Attacks, WiFi Pineapple, Similar SSID, OPN Network…

eBPF-based runtime kernel security monitor detecting exploits and rootkits via control flow integrity (wCFI) and privilege escalation detection (PSD)…

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

Linux kernel integrity monitor for detecting syscall hooking

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

Zabbix Template to monitor for Windows Event Viewer event's related to Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472. Monitors event…

Deceptive honeypot designed to simulate and monitor exploitation attempts targeting CVE-2026-0300, capturing attacker behavior for analysis and…

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…


ETW based POC to identify direct and indirect syscalls

pySigma OpenSearch backend