
psad
psad: Intrusion Detection and Log Analysis with iptables

psad: Intrusion Detection and Log Analysis with iptables

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

Practical labs, notes, and reports for CEH v13 modules — covering web hacking, network pentesting, malware analysis, social engineering, and security…

Network packet sniffer for real-time traffic capture, HTTP inspection, raw payload analysis, and device discovery with built-in man-in-the-middle…

Multi-threaded port scanner with TCP/UDP support, banner grabbing, and Shodan integration for enhanced network reconnaissance and vulnerability…

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

Convert raw HTTP requests/responses into PCAP files for testing Snort IDS rules and network security analysis. Supports Docker deployment and…

It was developed to speed up the processes of SOC Analysts during analysis

Formal modeling and analysis framework for hidden communication systems, enabling specification of covert channels, adversary models, and statistical…

IPv6 analysis tool: the other side

Programmable packet inspection engine with NIDS, DNS classification, frequency analysis, and auto-regex generation. Supports Python/Ruby/Java/Lua…

Zeek package detecting CVE-2021-42292 Microsoft Excel local privilege escalation exploit via network traffic analysis of spreadsheet downloads.

Basic log analysis tool to detect impossible travel via IP address geographic information

Lightweight telnet honeypot for capturing IoT malware samples and identifying active command-and-control infrastructure, designed for educational…

CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain…

A pcap capture analysis helper

Graph-first network traffic visualizer for live capture and PCAP replay with checkpoint diffing, path tracing, and Wireshark-style display filters…

Zeek package detecting CVE-2022-26937 exploitation attempts against Windows NFS servers via Network Lock Manager protocol analysis.