
winevt_logs_analysis
Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

A wireshark plugin to instrument ETW

Runs custom filters on Elasticsearch and alerts on matches

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

DECeption with Evaluative Integrated Validation Engine (DECEIVE): Let an LLM do all the hard honeypot work!

Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…

A host-based IDS and network monitoring system (My graduation project)

TrustedSec Sysinternals Sysmon Community Guide

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…