
GPEWebDefender
Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

Практические кейсы по информационной безопасности: развёртывание SIEM Wazuh и эксплуатация CVE-2021-41773

Easy-to-use live forensics toolbox for Linux endpoints

Centralize Management of Intrusion Detection System like Suricata Bro Ossec ...

VirusTotal Wanna Be - Now with 100% more Hipster

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)


Dockerized honeypot for CVE-2021-44228.

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.


Graph platform for Detection and Response

RedEye is a visual analytic tool supporting Red & Blue Team operations

Create actionable data from your Vulnerability Scans

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management