
SyntheticSun
Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

amavis is a high-performance email content filter framework written in Perl.

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints,…

Modular malware analysis artifact collection and correlation framework

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Structured guide to threat hunting using Zeek logs, aligned with MITRE ATT&CK framework for proactive detection of adversary tactics and techniques.

Privacy-first behavioral intelligence framework for multi-platform analysis and sociodynamic research.

OWASP Ontology-driven Threat Modelling framework

A LSTM based framework for handling multiclass imbalance in DGA botnet detection


Open Source Link Analysis & OSINT Framework

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Hermes — an ephemeral, Docker-powered OSINT framework for testing, tinkering, and secure investigative automation.

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

A simple and scalable Android bot emulation framework, as presented at Black Hat Europe 2021's Arsenal, as well as atHack 2021's Arsenal