
DeTTECT
Detect Tactics, Techniques & Combat Threats

Detect Tactics, Techniques & Combat Threats

Basic log analysis tool to detect impossible travel via IP address geographic information


This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

A Simple Log4j Indicator of Compromise Linux Detector

A Zeek OpenVPN protocol analyzer plugin.

Bro analyzer that detects Google's QUIC protocol

analyze a web-based network traffic 🕶 to detect central command and control servers

This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771



A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

An Active Defense and EDR software to empower Blue Teams