
ESFang
ESF modular ingestion tool for development and research.

ESF modular ingestion tool for development and research.

Evtx Log (xml) Browser

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

GitHub mirror of the Linux Kernel's audit repository

Detection of Manjusaka C2 framework

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

OWASP Honeypot, Automated Deception Framework.

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Detection framework for CVE-2025-32463 sudo privilege escalation vulnerability. Provides real-time monitoring, forensic analysis, and SIEM…

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

Incident Response Forensic Framework


SQL powered operating system instrumentation, monitoring, and analytics.

Dshell is a network forensic analysis framework.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…