
sysmon-config
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

A host based IDS written in C# Targetted at Metasploit

Host IDS for desktop users

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Github mirror of official Kismet repository

Best Practice Auditd Configuration

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM

The Sigma command line interface based on pySigma

Capturing, analysing and responding to cyber attacks

Security Tool to detect arp poisoning attacks

A host-based IDS and network monitoring system (My graduation project)


Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…