
EDR-Telemetry
This project aims to compare and evaluate the telemetry of various EDR products.

This project aims to compare and evaluate the telemetry of various EDR products.

Community-driven project for documenting, standardizing, and modeling security event logs to improve detection analytics and data normalization…

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

This project is a SIEM with SIRP and Threat Intel, all in one.

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

A host-based IDS and network monitoring system (My graduation project)

Hands-on project demonstrating Log4Shell exploitation, detection engineering with Splunk and auditd, and validated remediation in a containerized…

Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project…

This project explores whether modern OpenSSH reveals valid usernames through subtle response or timing differences. CVE-2016-6210 user enumeration…

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack…

This repository contains an academic and technical analysis of CVE-2023-34362, a critical SQL injection vulnerability affecting the MOVEit Transfer…

A lightweight, real-time Security Information and Event Management (SIEM) dashboard built using Streamlit. It collects system logs, detects USB and…

A modern and elegant dashboard for network traffic visualization and analysis.

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

Rules generated from our investigations.

Reference mapping Windows telemetry events—Sysmon, Security Auditing, and Threat Intelligence ETW—to underlying API functions, helping defenders…