
wireshark-forensics-plugin
Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…


Zeek package that detects CVE-2022-22954 exploit attempts, logs exploit URIs and attacker response data to aid in incident response and network…

Detection content for CVE-2026-22557 — UniFi Network Application unauthenticated path traversal (CVSS 10.0). Includes YARA, Sigma, KQL, Splunk SPL,…


This is the development tree. Production downloads are at:

Easy automated vulnerability scanning, reporting and analysis

Sysmon configuration file template with default high-quality event tracing

Security event correlation engine for ELK stack

Kvasir: Penetration Test Data Management

A repository to share publicly available Velociraptor detection content

A honeypot for the Log4Shell vulnerability (CVE-2021-44228).

Go library for parsing and executing Sigma detection rules against log entries, supporting field modifiers, CIDR matching, and custom field resolvers…

OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.

Zeek package for detecting Log4j CVE-2021-44228 exploit attempts via HTTP header payloads, LDAP Java class downloads, and second-stage Java class…

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

Wazuh detection rules for CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite, monitoring web access logs and zimbra.log for…

Detection signatures for CVE-2026-41940 and shemas for cPanel logs