
Zircolite
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

GitHub mirror of the Linux Kernel's audit repository

eBPF-powered Linux observability with AI incident detection. AGPL-3.0 licensed.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Kernel-level security & attack response for Linux servers.

A Simple Log4j Indicator of Compromise Linux Detector

Lightweight security state inspector for Linux — bridging the gap between pretty fetch tools and heavy-duty audit frameworks.

Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across…

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

Provides BigFix Fixlets and analyses to detect Log4j vulnerabilities (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105) across Windows and Linux…

Multi-OS vulnerability checker for CVE-2026-31431 (Linux kernel) and CVE-2026-41940 (cPanel)

CVE-2026-31431 Copy Fail Linux kernel vulnerability detection script

Defensive IR playbook and detection package for CVE-2026-31431 (Copy Fail) Linux kernel LPE, including Sigma, auditd, Falco, Wazuh, YARA, eBPF, and…

Lab validation report and detection artifacts for CVE-2026-43284 (DirtyFrag) Linux LPE. Provides auditd telemetry, event correlation rules, and…

Performed a live cybersecurity assessment on a university Linux server. During analysis, active attack activity was identified, including brute-force…

Patching CVE-2025-27558 vulnerability that had affected my linux image.