
ARTIF
An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

SQL powered operating system instrumentation, monitoring, and analytics.

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.


Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Dshell is a network forensic analysis framework.

Incident Response Forensic Framework

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Database Driven DNS Server with a Web UI

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

Single-page web dashboard for Meshtastic mesh networks with live network mapping, packet analysis, chat, sensor telemetry, and topology…

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

EXIST is a web application for aggregating and analyzing cyber threat intelligence.

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Next-Gen GUI-based WiFi and Bluetooth Analyzer for Linux