
crowdsec
Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Open Source Intelligence Interface for Deep Web Scraping

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring,…

A utility to safely generate malicious network traffic patterns and evaluate controls.

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

A tool to perform various OSINT techniques, aggregate all the raw data, visualise it on a dashboard, and facilitate alerting and monitoring on the…

DECeption with Evaluative Integrated Validation Engine (DECEIVE): Let an LLM do all the hard honeypot work!

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

Purpleteam scripts simulation & Detection - trigger events for SOC detections

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

A high interaction SSH honeypot

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally