
KQL-threat-hunting-queries
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

Detection rule validation

This repository includes the source code used in the "Characterization and Detection of Cross-Router Covert Channels" paper.

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Curated list of threat detection and hunting resources: detection rules, SIEM and log analysis tools, endpoint/network monitoring, datasets,…

A network packet forensics tool for SSH

A host-based IDS and network monitoring system (My graduation project)

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

Elastic version of SOC prime watcher rules

Spip network sensor written in Go

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…

Demo for detection and mitigation of HTTP/2 Rapid Reset vulnerability (CVE-2023-44487)

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma