
dsiem
Security event correlation engine for ELK stack

Security event correlation engine for ELK stack

A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without…

DShield Sensor Log Collection with ELK

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

eBPF Security Monitoring and Sandboxing Agent Based on Aya

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Anti-Virus for K8s. Protect your Applications running on Kubernetes from malicious attacks with pre-registered source code, runtime processes…

Defensive IR playbook and detection package for CVE-2026-31431 (Copy Fail) Linux kernel LPE, including Sigma, auditd, Falco, Wazuh, YARA, eBPF, and…

Hardened container staging framework with seccomp syscall whitelisting and eBPF telemetry to detect and block container escape and kernel ULP…

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

A honeypot for the Log4Shell vulnerability (CVE-2021-44228).

Lab for the CVE-2024-27198

Automate the creation of a lab environment complete with security tooling and logging best practices

Kubernetes-native CVE-2026-31431 mitigation with automated kernel module blocking, runtime Falco detection rules, and bashible-based node…

Best Practice Auditd Configuration

SOC detection and incident response lab simulating CVE-2024-27198 authentication bypass in JetBrains TeamCity. Includes ELK SIEM, Suricata IDS, Sigma…

CVE proof-of-concept labs, exploit scripts, and detection/prevention rules (Nginx, Apache, Snort, YARA) for high-severity CVEs. Authorized security…
