
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Building 70 Projects ranging from beginner to advanced so anyone can — learn from, build upon, use as a reference, or even copy directly. Gamified…

Sniffs sensitive data from interface or pcap

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

Perform a MitM attack and extract clear text credentials from RDP connections

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

enum4Linux is a Linux alternative to enum.exe for enumerating data from Windows and Samba hosts

Open-source RDP client for connecting to Windows Terminal Services from Unix-like systems, supporting RDP versions 4 and 5 with smart-card…

Signatures and IoCs from public Volexity blog posts.

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Generate firewall ACLs for Cisco, Juniper, Palo Alto, and more from a single YAML policy language via CLI or Python API.

Ultimate Network Stealther that makes Linux a Ghost In The Net and protects from MITM/DOS/scan

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

Pulled Pork for Snort and Suricata rule management (from Google code)

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

This is a mini-firewall that completely isolates a target device from the local network.

Enumerate information from NTLM authentication enabled web endpoints 🔎

Suspicious DGA from PDNS and Sandbox.