
SDK
SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

This repository contains indicators of compromise (IOCs) of our various investigations.

Slides and materials from conference presentations

A curated knowledge base to build, run and mature a SOC (including CSIRT).

TAXII server implementation in Python from EclecticIQ

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.


Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

MAPS cloud scanner and response parser for Microsoft Defender research.

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…


Apache Real Time Logs Analyzer System

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…