
TelemetrySource
Reference mapping Windows telemetry events—Sysmon, Security Auditing, and Threat Intelligence ETW—to underlying API functions, helping defenders…

Reference mapping Windows telemetry events—Sysmon, Security Auditing, and Threat Intelligence ETW—to underlying API functions, helping defenders…

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

Community-driven project for documenting, standardizing, and modeling security event logs to improve detection analytics and data normalization…

A host-based IDS and network monitoring system (My graduation project)

Blue Team detection lab created with Terraform and Ansible in Azure.

This project aims to compare and evaluate the telemetry of various EDR products.

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

Restructured and Collaborated SIEM and CVSS Infrastructure. Presented at Blackhat Asia Arsenal 2020.

Rules generated from our investigations.

Advanced detection of port scanning, DoS and malware attacks using Machine Learning techniques

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

Pivotable Reverse WhoIs / PDNS Fusion with Registrant Tracking & Alerting plus API for automated queries (JSON/CSV/TXT)

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

AI 驱动的 SOC 仿真平台