
Incident-Analysis-Response-Check-Point-Security-Gateway-CVE-2024-24919-LFI-Exploitation
Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Zeek script and Python utility to enrich network security monitoring logs with CVE identifiers for improved threat intelligence and vulnerability…

Curated indicators of compromise (IOCs) for CVE-2019-19781, including IP addresses and whois data from honeypot logs to aid threat detection and…

Educational demo of CVE-2020-1472 (ZeroLogon) detection using Windows Event Logs and Suricata IDS, plus mitigation via Windows Updates. Includes…

Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Medium-interaction SSH honeypot that logs brute force attacks and full attacker shell interactions, with customization options to reduce…

CitrixBleed 2 NetScaler honeypot logs

WireGuard-based zero-trust access platform providing secure, peer-to-peer remote access with granular policy controls, SSO authentication, and audit…

Desktop monitoring and local security reviews for AI agents, with opt-in policy-controlled execution and MCP action tools. Windows primary;…

Redirect All Traffic Through Tor Network For Kali Linux

DShield Sensor Log Collection with ELK

Zeek package for tracking long connections to report them before they have completed.

Corelight or Zeek Elastic Common Schema Templates

Is this IP a C2 server?

Chronicle parser for CORELIGHT and related information.

Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts