
phantom-playbooks
Automated security incident response playbooks for Splunk Phantom, integrating Zeek logs, DNS analysis, and VirusTotal threat intelligence to…

Automated security incident response playbooks for Splunk Phantom, integrating Zeek logs, DNS analysis, and VirusTotal threat intelligence to…

Forensic triage toolkit for Citrix NetScaler devices, featuring a Dissect-based IOC scanner for webshells, timestomping, and suspicious binaries,…

Defensive PoC decoy for CVE-2025-59287 (WSUS) - emulates WSUS endpoints, captures request bodies and metadata, saves evidence for forensic analysis,…

Bash-based scanner detecting indicators of compromise from CVE-2023-3519 exploitation on Citrix ADC appliances, supporting live and forensic image…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Ruby On Rails Application For Network Security Monitoring

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

DShield Sensor Log Collection with ELK

TheLightScope

analyze a web-based network traffic 🕶 to detect central command and control servers

Mapping Corelight or Zeek data to Elastic Common Schema logs

Analyze Windows Firewall outbound blocks and selectively allow traffic

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Corelight app for CrowdStrike LogScale and Next-Gen SIEM