
nono
safe execution paths for agents - zero trust, zero setup, zero latency.

safe execution paths for agents - zero trust, zero setup, zero latency.

E-mails, subdomains and names Harvester - OSINT

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

DShield Sensor Log Collection with ELK

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Mapping Corelight or Zeek data to Elastic Common Schema logs

Mapping Corelight or Zeek data to Elastic Common Schema fields

This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

CVE-2026-48907

Automated BloodHound graph updater for blue teams. Enriches AD attack paths with real-time session, group, and CVE data from SIEMs, enabling…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

A python package for use in generating fake data for SOC and security automation.

Your Swiss Army knife to analyze malicious web traffic based on the popular Fiddler web debugger.

Python Decoders for Common Remote Access Trojans