
PacketPirate
A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

Kernel-mode filter driver that monitors ConDrv traffic to detect mimikatz execution in real-time, logging detection events via ETW for incident…

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Hands-on detection research repository documenting how APT techniques appear in logs, with practical detection logic, Splunk queries, and Sigma rules…

The Sigma command line interface based on pySigma

End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack…