
fail2ban
Daemon to ban hosts that cause multiple authentication errors

Daemon to ban hosts that cause multiple authentication errors

Network-aware SSH router - routes connections to different IPs/ports/keys/jump hosts based on active VPN or network

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

DHCP exhaustion script written in python using scapy network library

Parallel SSH service discovery and security auditor that scans any port, validates SSH banners, and audits authentication methods, weak cryptography,…

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

Like Envoy xDS, but for eBPF filters

scanner for CVE-2020-0796

enum4Linux is a Linux alternative to enum.exe for enumerating data from Windows and Samba hosts

SSH posture helper for CVE-2026-31431 (Copy Fail): kernel and algif_aead inventory

Multi-host UFW firewall dashboard — explains rules in plain English, detects security gaps, and provides connection diagnostics

Detection script for telnetd CVE-2026-32746 that probes remote hosts to identify vulnerable LINEMODE support via TCP connection, generating detection…

Rule-based linter for OpenSSH client config files that detects duplicate hosts, missing identity files, weak algorithms, wildcard ordering issues,…

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

smbcrawler is no-nonsense tool that takes credentials and a list of hosts and 'crawls' (or 'spiders') through those shares

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

Scanner and attack suite for hosts that forward unauthenticated packets via IPIP and GRE protocols. (CVE-2020-10136 CVE-2024-7595)