
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Centralized log management platform for collecting, indexing, and analyzing streaming logs, with alerting and event correlation for security…

Passive DNS Capture and Monitoring Toolkit

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Security Governance for Agentic AI

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

TrustedRouter.com repo for secure LLM proxying

PHP 8.4+ security library (mirror)

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

A Python package and CLI for parsing aggregate and forensic DMARC reports

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

Develop, validate, and publish SIEM detection rules for Elastic Security, with Python CLI tooling, KQL parsing, Kibana integration, and packaged…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Android Logs Events And Protobuf Parser