
CVE-2007-2447-Exploitation-SIEM-Detection-Lab
Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)


Strelka Web UI for File Submission and Analysis

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

analyze a web-based network traffic 🕶 to detect central command and control servers

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.


Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

Web-based tool for managing and deploying Sysmon configurations across Windows endpoints via agentless (WMI/SMB) or agent-based methods, with remote…

Apache Real Time Logs Analyzer System

A collection of scripts which may come in handy during your freedom fighting activities.

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Next-Gen GUI-based WiFi and Bluetooth Analyzer for Linux

gundog - guided hunting in Microsoft Defender

Incident Response collection and processing scripts with automated reporting scripts