
log-horizon
Microsoft Sentinel SIEM Log Source Analyzer

Microsoft Sentinel SIEM Log Source Analyzer

Universal mobile devtool for Agents & Humans - control iOS Simulators, Android Emulators, and real devices from a single dashboard and CLI

A python package for use in generating fake data for SOC and security automation.

Primary data pipelines for intrusion detection, security analytics and threat hunting

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack…

Remediation report for MegaQuagga Publishing validating the mitigation of CVE-2019-9978 through progressive defensive layering. Documents reverse…

Some Threat Hunting queries useful for blue teamers

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

A Zeek OpenVPN protocol analyzer plugin.

Rules generated from our investigations.

Sigma rules from Joe Security

A tool to subscribe to receive all standard Android broadcasts on your Android device.

Sigma rules to share with the community