
FalconEye
Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.

Detection rule validation

The Intelligent Process Lifecycle of Active Cyber Defenders

Sigma rule for detecting exploitation of CVE-2022-30190 (Follina) via Windows process creation events, enabling SOC teams to identify malicious…

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.