
ThreatIngestor
Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

Zeek plugin for detecting and parsing OpenVPN traffic (UDP/TCP with TLS), extracting session and TLS handshake metadata for network security…

Passive wireless network detector, sniffer, and intrusion detection system supporting Wi-Fi, Bluetooth, SDR, and other radio protocols for real-time…

WordPress honeypot that detects probes for plugins, themes, and common fingerprinting files. Configurable via CLI or config file, with theme and…

Deceptive MySQL honeypot exploiting LOAD DATA LOCAL INFILE to read Windows files from attackers, capturing WeChat ID, phone number, and location data…

Probabilistic measurement script for Bro/Zeek that tracks top DNS queries by type over configurable intervals, logging results to a dedicated log for…

Lightweight low-interaction network honeypot sensor that captures TCP payloads, performs passive TLS/HTTP/SSH fingerprinting, and outputs structured…

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

Modular open-source framework for automated botnet monitoring with customizable protocol support, client behavior, data logging, and distributed task…

Zeek script that enriches DNS logs with ICANN TLD, domain, and subdomain fields, and marks trusted domains for threat detection.

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Primary data pipelines for intrusion detection, security analytics and threat hunting

Training-free anomaly detection framework using Shannon Entropy, Fisher Information, and Wasserstein Distance to map system states into geometrically…

Integrates your Modern Honeypot Network Server and Wordpress Blog via MHN's REST API and WP's shortcodes

Medium-interaction SSH honeypot that logs brute force attacks and records full attacker shell interactions with a fake filesystem for threat…