
FileWatchTower
FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

Lightweight security state inspector for Linux — bridging the gap between pretty fetch tools and heavy-duty audit frameworks.

A lightweight, real-time Security Information and Event Management (SIEM) dashboard built using Streamlit. It collects system logs, detects USB and…

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy

This project aims to compare and evaluate the telemetry of various EDR products.

Community-driven project for documenting, standardizing, and modeling security event logs to improve detection analytics and data normalization…

This project is a SIEM with SIRP and Threat Intel, all in one.

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

A host-based IDS and network monitoring system (My graduation project)

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

This project explores whether modern OpenSSH reveals valid usernames through subtle response or timing differences. CVE-2016-6210 user enumeration…

Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project…

End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack…