
Detect-BlueKeep
a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)

a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)

Automated Network Security with Rust: Detecting and Blocking Port Scanners

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Corelight@Home script

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

A network packet forensics tool for SSH

Detection rule validation

Monitors Asterisk authentication logs and automatically bans IPs with repeated failed login attempts using iptables, with configurable thresholds and…

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

RPi3+ Network Cracker Setup Tool

Automate the creation of a lab environment complete with security tooling and logging best practices

OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.

A tool for malicious behavior detection in IoT devices

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…