
ToolShell-Honeypot
Honeypot for CVE-2025-53770 aka ToolShell

Honeypot for CVE-2025-53770 aka ToolShell
Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

eBPF Security Monitoring and Sandboxing Agent Based on Aya

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

Anti-Virus for K8s. Protect your Applications running on Kubernetes from malicious attacks with pre-registered source code, runtime processes…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228

Detection script for CVE-2026-31431 (Copy Fail) that checks kernel version, patch presence, kernel configs, AF_ALG socket availability, setuid…

Docker configuration to quickly setup your own Canarytokens.

A Linux Host-based Intrusion Detection System based on eBPF.

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Best Practice Auditd Configuration

CVE-2020-0618 Honeypot

Documentation and scripts to properly enable Windows event logs.

Ruby On Rails Application For Network Security Monitoring