
SOC235---Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515
SOC analyst walkthrough triaging a Confluence CVE-2023-22515 broken access control exploitation attempt, covering log analysis, MITRE ATT&CK mapping,…

SOC analyst walkthrough triaging a Confluence CVE-2023-22515 broken access control exploitation attempt, covering log analysis, MITRE ATT&CK mapping,…

Leitwacht control plane — runtime security for GitLab Runner CI/CD: policy authoring, multi-tenancy, audit, GitLab integration

CVE analysis of CVE-2025-40536, SolarWinds Web Help Desk security control bypass (CVSS 8.1). Covers vulnerability mechanics, attack chain with…

High fidelity defensive security lab simulating a DoD aligned enterprise network with Active Directory, VLAN segmentation, STIG based hardening,…

Detects phi-structured C2 beacons that evade RITA and standard regularity-based detectors

Kalim backdooe Malware Report


Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)

Zeek detector for QuasarRat

CVE-2025-33073 Research writeup

Real-time geospatial OSINT platform aggregating 60+ public telemetry feeds (ADS-B, AIS, satellites, CCTV) into a unified map with server-side recon…

A utility to safely generate malicious network traffic patterns and evaluate controls.

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Hunts out CobaltStrike beacons and logs operator command output

a guard that blocks catastrophic agent actions

An open-source framework for verifiably private AI inference