
iMonitor
Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Detection reverse shell and kill it before trying shell.

Elastic Security detection content for Endpoint

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

Low-interaction honeypot that emulates vulnerable network services to capture malware, shellcode, and exploit attempts, with IPv6 and TLS support.

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

Windows Analysis and Research Toolkit

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Linux Kernel Runtime Integrity with eBPF

ETW based POC to identify direct and indirect syscalls

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…


A host based IDS written in C# Targetted at Metasploit

A home for detection content developed by the delivr.to team


A tool to assist with network-based hunting for GRU's Drovorub malware c2

Zeek script that monitors SMB traffic and alerts on known ransomware filenames using the Anti-Ransomware File System Resource Manager list.