
packetStrider
A network packet forensics tool for SSH

A network packet forensics tool for SSH

Security research on Erlang/OTP SSH CVE-2025-32433.

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…


A high interaction SSH honeypot

Fingerprint SSH clients and servers.

PEAK Baseline Threat Hunt dashboards for Security Onion 3.0 — covering DNS, HTTP, TLS, SMB, Kerberos, SSH, RDP, DCE/RPC, LDAP, Modbus, DNP3,…

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Experimental Decoy Broker

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…