
securityonion
Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Dshell is a network forensic analysis framework.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!


Web-based Traffic and Cybersecurity Network Traffic Monitoring

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Zeek support for Community ID flow hashing.

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

A flow-based network monitor with Deep Packet Inspection

Bro analyzer that detects Google's QUIC protocol

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…