
detection-validation
Detection rule validation

Detection rule validation

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

A network packet forensics tool for SSH

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Lightweight Go toolkit plus a Dockerized Next.js lab to explore and triage CVE-2025-55182.

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

A utility to safely generate malicious network traffic patterns and evaluate controls.

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

A Go library for using zeek broker's websocket API

eBPF-based runtime detector for container breakout vulnerabilities in runc and Docker, monitoring syscalls and Docker daemon calls to detect…

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

Metlo is an open-source API security platform.

Galah: An LLM-powered web honeypot.

Linux Kernel Runtime Integrity with eBPF

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

Elastic version of SOC prime watcher rules