
Leaktopus
Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…


DShield Sensor Log Collection with ELK

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

This project is a SIEM with SIRP and Threat Intel, all in one.

Event Trace Log file parser in pure Python

A python package for use in generating fake data for SOC and security automation.

Spip network sensor written in Go

SOC detection and incident response lab simulating CVE-2024-27198 authentication bypass in JetBrains TeamCity. Includes ELK SIEM, Suricata IDS, Sigma…

Multi-host UFW firewall dashboard — explains rules in plain English, detects security gaps, and provides connection diagnostics

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

Detection rules and YARA/KQL signatures for CVE-2025-60787, an unauthenticated RCE in motionEye via config injection, with process execution and file…

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

Automate the creation of a lab environment complete with security tooling and logging best practices

eBPF-based Linux security monitor and threat hunter providing chronologically ordered, container-aware events with on-host correlation for incident…

OWASP Honeypot, Automated Deception Framework.