
subcrawl
Modular framework for discovering and analyzing open directories on the web. Crawls URLs, extracts content, applies YARA/ClamAV scanning, and outputs…

Modular framework for discovering and analyzing open directories on the web. Crawls URLs, extracts content, applies YARA/ClamAV scanning, and outputs…

A Software as a Service (SaaS) log collection framework.

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

amavis is a high-performance email content filter framework written in Perl.

YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

OWASP Ontology-driven Threat Modelling framework


A LSTM based framework for handling multiclass imbalance in DGA botnet detection

Open Source Link Analysis & OSINT Framework

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

LLM-first deception framework: "The honeypot that talks back!™"

A simple and scalable Android bot emulation framework, as presented at Black Hat Europe 2021's Arsenal, as well as atHack 2021's Arsenal

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

Detection of Manjusaka C2 framework