
Sigma
A repository to release detection rules to the public

A repository to release detection rules to the public

GreyEnergy Mini Module Malware Analysis (Turkish)

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

Cortex: a Powerful Observable Analysis and Active Response Engine

Shell Companies Inside Apple's Privacy Relay

This is the development tree. Production downloads are at:

German OWASP Day conference site & presentation archive

Scripts for communication with Bunitu Trojan C&Cs

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)


OpenDNS Data Visualization Framework

Malware analysis from the domain goxlr.net

goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current privilege…

End-to-end SOC investigation: CVE-2011-2523 kill chain, multi-source log correlation, incident report — MITRE ATT&CK T1190

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

Kaspersky's GReAT KLara

Dynamically generated Suricata rules from real-time threat feeds