
CVE-2022-24491
Zeek-based network detector for CVE-2022-24491, monitoring RPC portmap set and dump actions to identify exploit attempts in real-time traffic.

Zeek-based network detector for CVE-2022-24491, monitoring RPC portmap set and dump actions to identify exploit attempts in real-time traffic.

Network anomaly detector that monitors raw packets to identify port scanning activity in real time, with flexible sniffing duration controls and live…

Security Tool to detect arp poisoning attacks

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)

Ability to detect suspicious activity such as (WEP/WPA/WPS) attack by sniffing the air for wireless packets.

A network packet forensics tool for SSH

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Corelight@Home script

Machine Learning based Intrusion Detection Systems are difficult to evaluate due to a shortage of datasets representing accurately network traffic…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Zeek package that detects CVE-2022-22954 exploit attempts, logs exploit URIs and attacker response data to aid in incident response and network…

AV/EDR Lab environment setup references to help in Malware development

CVE-2020-0618 Honeypot

Primary data pipelines for intrusion detection, security analytics and threat hunting

Top DNS Measurement for Bro
