
ModSecurity
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Hunts for potential malware downloads and suspicious domain calls via common Windows LOLBins using YARA rules and Nexthink telemetry modules.

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Ruby On Rails Application For Network Security Monitoring

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Go library for parsing and executing Sigma detection rules against log entries, supporting field modifiers, CIDR matching, and custom field resolvers…

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

Chronicle parser for CORELIGHT and related information.

Detects shadow-administrator accounts in WordPress via configurable indicators and heuristics, then removes selected accounts through guarded, logged…

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

Restructured and Collaborated SIEM and CVSS Infrastructure. Presented at Blackhat Asia Arsenal 2020.

Runs custom filters on Elasticsearch and alerts on matches