
prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

A python script to query the MITRE ATT&CK API for tactics, techniques, mitigations, & detection methods for specific threat groups.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Real-time geospatial OSINT platform aggregating flight, vessel, and satellite data with dark web search, social media dorking, and AI-powered…

A containerized enterprise-style lab for researching and defending against CVE-2026-27483.

Cloud-native system telemetry pipeline that collects, processes, and exports system call events into a compact object-relational format for…

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

Local, monitor-first observability for AI agents: processes, file activity, TCP endpoints and attribution evidence. Windows primary; macOS/Linux…

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT

Modular network scanning framework that integrates diverse tools and external databases to detect vulnerabilities and configuration errors, producing…

E-mails, subdomains and names Harvester - OSINT

Open-source email filtering framework that detects spam and phishing using content analysis, header checks, Bayesian scoring, and DNS blocklists.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems