
CloudGrappler
Query high-fidelity cloud detections for known threat actors across AWS, Azure, and GCP using CloudTrail logs and custom threat intelligence rules.

Query high-fidelity cloud detections for known threat actors across AWS, Azure, and GCP using CloudTrail logs and custom threat intelligence rules.

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Catch what's lurking in your Kafka clusters.

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

ML-driven threat detection and continuous monitoring platform built for federal zero trust architectures.

Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

Tuning and refactoring Google Chronicle Curated Detections to eliminate alert fatigue and fix logic gaps/bugs.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Powerful protection for AI agents - Open-source security and cost tracking for AI applications

Data from a BRAWL Automated Adversary Emulation Exercise

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Community-driven project for documenting, standardizing, and modeling security event logs to improve detection analytics and data normalization…

SécurixOS is a NixOS-based secure operating system tailored for small to medium-sized teams. It provides a minimal, hardened environment with strong…

The easiest, and most secure way to access and protect all of your infrastructure.