
FreeLabFriday_Labs
This repository contains all lab instructions for the following content: Info Sec Core Skills, SOC Core Skills, ADCD Labs, SOC Analyst Labs, & BnB…

This repository contains all lab instructions for the following content: Info Sec Core Skills, SOC Core Skills, ADCD Labs, SOC Analyst Labs, & BnB…

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Advanced Phishing Protection: Suricata rulesets open and free

An Open Harness and Benchmark for AI in Cybersecurity Operations.

Builds a root exploit for vivo/iQOO devices targeting CVE-2026-43499, leveraging kernel techniques like KASLR bypass and CFI manipulation to achieve…

An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…

Installable Claude Skills providing expert-level compliance guidance for 30+ frameworks including ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF,…

Open-source silicon RTL and simulation tools for the Baochip 1x SoC, featuring a VexRiscv CPU, Verilator-based verification, and documentation for…

Open-source security orchestration, automation, and response (SOAR) platform with a visual workflow editor, prebuilt security app integrations, and…

Defensive engagement & threat intelligence research laboratory. Converts inbound scam emails into actionable IOCs through controlled, policy-driven…

Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs…

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated…

Documented SOC automation workflow using Wazuh, N8N, Caldera, and Velociraptor

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…