
GPEWebDefender
Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Monitors Windows Security logs for failed RDP attempts and automatically blocks abusive IPs via Windows Firewall, with configurable thresholds and…

Provides packet processing capabilities for Go

DShield Sensor Log Collection with ELK

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Selective protocol extractor from PCAPs or interfaces

A flow-based network monitor with Deep Packet Inspection

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Automated security incident response playbooks for Splunk Phantom, integrating Zeek logs, DNS analysis, and VirusTotal threat intelligence to…

Structured guide to threat hunting using Zeek logs, aligned with MITRE ATT&CK framework for proactive detection of adversary tactics and techniques.

Zeek support for Community ID flow hashing.

Zeek script and Python utility to enrich network security monitoring logs with CVE identifiers for improved threat intelligence and vulnerability…

Zeek package for tracking long connections to report them before they have completed.

Bro analyzer that detects Google's QUIC protocol

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…