
mcp-attack-detection-sentinel
Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Tools for investigating Log4j CVE-2021-44228

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)

Training-free anomaly detection framework using Shannon Entropy, Fisher Information, and Wasserstein Distance to map system states into geometrically…

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

A Wordpress Honeypot

Primary data pipelines for intrusion detection, security analytics and threat hunting

MysqlHoneypot

Top DNS Measurement for Bro

A Zeek OpenVPN protocol analyzer plugin.

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Just a git repo for the sleepmask detection rule i found in https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike/sleep-…