


A flow-based network monitor with Deep Packet Inspection

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Zeek support for Community ID flow hashing.

Bro analyzer that detects Google's QUIC protocol



Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

Network Security Monitoring on Raspberry Pi type devices

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Easy automated vulnerability scanning, reporting and analysis

Web-based network monitoring system providing real-time bandwidth tracking, server performance metrics, and customizable alerts for proactive network…

Enhanced SSH client with TUI — manage connections, keys, and sessions

Analyze Windows Firewall outbound blocks and selectively allow traffic

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…

A Bro package to identify connections that are bursting (lots of data and transferring quickly).

Corelight Dashboards and Parsers for Sentinel One Singularity

Corelight app for CrowdStrike LogScale and Next-Gen SIEM