
NetAlertX
Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

A tool to monitor local network traffic for possible security vulnerabilities. Warns user against possible nmap scans, Nikto scans, credentials sent…

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

Automate stopping bad bots from accessing your server

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐

By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

Network anomaly detector that monitors raw packets to identify port scanning activity in real time, with flexible sniffing duration controls and live…

Advanced detection of port scanning, DoS and malware attacks using Machine Learning techniques

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.

Multi-threaded network intrusion detection and prevention system with rule-based detection, protocol-aware inspection, and pcap analysis for…