
brawl-public-game-001
Data from a BRAWL Automated Adversary Emulation Exercise

Data from a BRAWL Automated Adversary Emulation Exercise

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

Mapping Corelight or Zeek data to Elastic Common Schema fields

Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.

TheLightScope

Detection Script for MongoBleed Exploitation

Zeek package for tracking long connections to report them before they have completed.

Cyber Threat Defense World Modeling

Mapping Corelight or Zeek data to Elastic Common Schema logs

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

An open-source, single-script CVE scanner for RMM-managed fleets. Pure PowerShell 7 — joins your RMM software inventory against NVD, CISA KEV, EPSS…


A Zeek OpenVPN protocol analyzer, based on Spicy.

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

Content packs for Eventum

A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner