
routeros-scanner
Tool to scan for RouterOS (Mikrotik) forensic artifacts and vulnerabilities.

Tool to scan for RouterOS (Mikrotik) forensic artifacts and vulnerabilities.

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Forensic triage toolkit for Citrix NetScaler devices, featuring a Dissect-based IOC scanner for webshells, timestomping, and suspicious binaries,…

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Minimal Redis honeypot detecting RediShell (CVE-2025-49844) exploits.

Defensive PoC decoy for CVE-2025-59287 (WSUS) - emulates WSUS endpoints, captures request bodies and metadata, saves evidence for forensic analysis,…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Patch for CVE-2018-1000140 in rsyslog's librelp library, fixing a remote code execution vulnerability in the reliable event logging protocol…

Pinned version of rsyslov vulnerable to CVE-2018-1000140

DShield Sensor Log Collection with ELK

Analyze Windows Firewall outbound blocks and selectively allow traffic

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

DECeption with Evaluative Integrated Validation Engine (DECEIVE): Let an LLM do all the hard honeypot work!

Ruby On Rails Application For Network Security Monitoring

Simple TCP/UDP honeypot implemented in Perl

A flow-based network monitor with Deep Packet Inspection

Detection of Manjusaka C2 framework