
ALEAPP
Android Logs Events And Protobuf Parser

Android Logs Events And Protobuf Parser

Develop, validate, and publish SIEM detection rules for Elastic Security, with Python CLI tooling, KQL parsing, Kibana integration, and packaged…

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Zero-dependency, sub-second Windows live digital forensics & incident response (DFIR) triage engine for USB responders.

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

Adaptive two-stage Layer 4 DDoS mitigation gateway using behavioral traffic analysis, Random Forest classification, and kernel-level ipset/iptables…

A Python package and CLI for parsing aggregate and forensic DMARC reports

Python CLI/TUI for forensic triage of Ubuntu systems — detects and remediates persistence mechanisms with artifact collection, timeline correlation,…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Corelight or Zeek Elastic Common Schema Templates

Microsoft Threat Intelligence Security Tools

Security Governance for Agentic AI

Single-page web dashboard for Meshtastic mesh networks with live network mapping, packet analysis, chat, sensor telemetry, and topology…

Defensive research tool that documents observable API endpoints and user agents of offensive tooling targeting Microsoft Entra ID, supporting…

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Research toolkit for analyzing AI agent behavioral patterns through multi-disciplinary corpus analysis. Parses session logs, runs 23 analytical…