
osquery
SQL powered operating system instrumentation, monitoring, and analytics.

SQL powered operating system instrumentation, monitoring, and analytics.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

GitHub mirror of the Linux Kernel's audit repository

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

A Software as a Service (SaaS) log collection framework.

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Detection framework for CVE-2025-32463 sudo privilege escalation vulnerability. Provides real-time monitoring, forensic analysis, and SIEM…

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Dshell is a network forensic analysis framework.

OWASP Honeypot, Automated Deception Framework.

Detection of Manjusaka C2 framework

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

Evtx Log (xml) Browser