
packetStrider
Analyzes SSH packet captures using machine learning to predict reverse tunnels, keystrokes, data exfiltration, and authentication methods for…

Analyzes SSH packet captures using machine learning to predict reverse tunnels, keystrokes, data exfiltration, and authentication methods for…

Network traffic inspection tool that reassembles TCP/UDP flows and inspects them using regex, fuzzy string matching, shellcode detection (libemu),…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Inspect live Windows system internals: processes, services, network, kernel callbacks, SSDT, and per-process anomalies; detect hooks and rootkits…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Zeek package and Suricata rules to detect ICMP ping tunnels associated with the Pingback C2 malware, enabling network defense against covert…

Structured taxonomy of network threats and tools for evaluating intrusion detection systems, with a focus on dataset relevance and threat…

Rust tool to detect cell site simulators on an orbic mobile hotspot

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Windows PowerShell tool for detecting LLMNR/NBNS spoofing attacks by sending requests and sniffing responses to identify malicious responders on the…

On-device runtime security for AI agents with 515+ detection rules and ML ensemble to stop prompt injection, jailbreaks, and tool attacks in under…

A tool for malicious behavior detection in IoT devices

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

A tool to generate Snort rules based on public IP reputation data

Security Tool to detect arp poisoning attacks

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…