
auditd
Best Practice Auditd Configuration

Best Practice Auditd Configuration

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Incident Response Forensic Framework

AI runtime inventory: discover shadow AI, trace LLM calls

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

The Intelligent Process Lifecycle of Active Cyber Defenders

Top DNS Measurement for Bro

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Zabbix Template to monitor for Windows Event Viewer event's related to Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472. Monitors event…

Centralize Management of Intrusion Detection System like Suricata Bro Ossec ...

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Express security essentials deployment for Linux Servers

Distributed & real time digital forensics at the speed of the cloud

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Medium-interaction SSH/Telnet honeypot built with Cowrie, Loki, Promtail, and Grafana - provisioned on DigitalOcean via Terraform with a GitLab CI…

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

simply nodes and graphs

Powershell module for VMWare vSphere forensics