
security-onion
Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Bro analyzer that detects Google's QUIC protocol


Dshell is a network forensic analysis framework.

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Zeek support for Community ID flow hashing.

A flow-based network monitor with Deep Packet Inspection

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…