
pySigma
Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Rust tool to detect cell site simulators on an orbic mobile hotspot

A tool to generate Snort rules based on public IP reputation data

Security Tool to detect arp poisoning attacks

A simple tool to detect NBT-NS and LLMNR spoofing (and messing with them a bit)

Small tool to play with IOCs caused by Imageload events

A tool to monitor local network traffic for possible security vulnerabilities. Warns user against possible nmap scans, Nikto scans, credentials sent…

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…

a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

Automated Network Security with Rust: Detecting and Blocking Port Scanners

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster