
crowdsec
Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

DECeption with Evaluative Integrated Validation Engine (DECEIVE): Let an LLM do all the hard honeypot work!

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Script to check if system are vulnable to cve-2026-23111

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring,…

Open Source Intelligence Interface for Deep Web Scraping

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

A terminal based tool that monitors real-time Bitcoin transactions above or below a specified threshold.

Purpleteam scripts simulation & Detection - trigger events for SOC detections

A utility to safely generate malicious network traffic patterns and evaluate controls.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

A high interaction SSH honeypot