
so-crates
SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

eBPF-powered silent observer for containerized runtimes, built for malware analysis sandboxes and Agentic AI monitoring.

Real-time, container-based file scanning at enterprise scale

Linux Persistence Detection, Hunting and Artifact Collection script

Detection and analysis toolkit for CVE-2026-31431 Linux LPE, providing Python and PowerShell scanners, YARA rules, and forensic analysis for active…

Research of CVE-2024-3094 vulnerability.

Public OCI-Image (docker image) Security Checker

Real-world attack log analysis of CVE-2025-66478 (Next.js Server Actions RCE) with malware samples, attacker IP tracking, and container security…

eBPF-based runtime security agent for Kubernetes that detects unknown processes and file changes, enforces pre-registered constraints, and automates…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.