
ThreatSentry-AI
ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

A simple bash script to check for evidence of compromise related to CVE-2024-3400

CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.

This repository contains informaion about the Fortigate firewall vulnerability (CVE-2022-40684) and affected data that were publicly disclosed by the…

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

A network sniffer that logs all DNS server replies for use in a passive DNS setup

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Zeek package for tracking long connections to report them before they have completed.

Mapping Corelight or Zeek data to Elastic Common Schema logs

A Zeek package to detect CVE-2021-42292, a Microsoft Excel local privilege escalation exploit.

Selective protocol extractor from PCAPs or interfaces

Originally a Honeypot for CVE-2026-20131
