
Aegis
OS-level monitor for AI agents: observes processes, file access, and network activity on the local machine and attributes each event to an agent…

OS-level monitor for AI agents: observes processes, file access, and network activity on the local machine and attributes each event to an agent…


Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Tools and Techniques for Blue Team / Incident Response

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

Strelka Web UI for File Submission and Analysis

Extensible MacOS system telemetry generator.

Real-time, container-based file scanning at enterprise scale

This is the development tree. Production downloads are at:

CVE-2026-54984 / ZDI-26-543: Windows ICC file parsing out-of-bounds write (CWE-122, CVSS 7.8)

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

This package extends the Intel package to log more fields

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…