
OneAlert
AI-powered SOC for OT/ICS networks — 6 autonomous agents, MITRE ATT&CK mapping, Suricata/Zeek ingestion, human-in-the-loop response, 330+ tests.…

AI-powered SOC for OT/ICS networks — 6 autonomous agents, MITRE ATT&CK mapping, Suricata/Zeek ingestion, human-in-the-loop response, 330+ tests.…

Zero-dollar attack surface management tool

Originally a Honeypot for CVE-2026-20131

Defensive exposure assessment tool for identifying externally accessible cPanel, WHM, and Webmail management interfaces related to CVE-2026-41940.

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

CVE-2019-19781 Attack Triage Script

Firewall rules to mitigate a zero-day vulnerability malware attack (CVE-2022-22965), known as Spring4Shell

A powerful and flexible tool to apply active attacks for disrupting stegomalware

Batch-mode checker for Shadowhammer malware indicators, scanning local or provided MAC addresses against known malicious hashes, with offline support…

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

An ssh honeypot with the XZ backdoor. CVE-2024-3094

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.

CitrixBleed 2 NetScaler honeypot logs

A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM: