
audit-kernel
Linux 内核审计(audit)仓库的 GitHub 镜像

Linux 内核审计(audit)仓库的 GitHub 镜像

CY376 蓝队项目 — pfSense DMZ、Suricata IDS/IPS 以及针对 CVE-2014-6271 的自动化主机加固

网络异常检测器,通过监控原始数据包实时识别端口扫描活动,提供灵活的嗅探持续时间控制,并实时输出端口列表。

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

通过可配置的指标和启发式规则检测 WordPress 中的影子管理员账户,然后通过受保护且记录日志的清理操作移除所选账户。不删除恶意软件。

用于实时流量检测、入侵检测与防御、协议分析以及基于规则的威胁狩猎的开源网络 IDS/IPS/NSM 引擎。


Windows Driver for Armadito

关于CVE-2026-43284(Dirty Frag)的全面技术研究,涵盖Linux内核内部机制、根因分析、补丁分析、检测工程、威胁狩猎、应急响应及Kubernetes安全影响。

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

在 Elasticsearch 上运行自定义过滤器,并在匹配时发出警报。

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research


🍯Honeypot Threat Intel

使用 Rust 实现自动化网络安全:检测与阻止端口扫描器