Showing 36 of 129 projects
A PowerShell script that monitors and logs newly created WMI consumers and processes to the Windows Application event log.
An open-source repository of cybersecurity detection rules and threat identifiers for security teams to enhance threat detection capabilities.
A practical classroom course suite teaching cyber defense monitoring using Suricata and Arkime for threat detection and packet analysis.
A honeypot that emulates USB storage devices to detect and capture malware that spreads via USB propagation.
A tool for Exchange administrators to detect malicious client-side rules, VBScript forms, and custom homepages used in attacks.
A honeypot that detects and logs exploitation attempts targeting the Log4Shell vulnerability (CVE-2021-44228).
Kernel-mode malicious activity hooking framework for macOS security analysis and malware research.
A set of Suricata IDS/IPS detection rules specifically designed to identify NMAP port scans across various scan types and speeds.
A Python utility for securely unpacking and staging suspicious files, designed for integration with malware analysis tools like Cuckoo Sandbox.
Analyzes web traffic via Squid proxy to detect command and control servers and malicious sites using Spamhaus data.
A simple and effective honeypot that mimics phpMyAdmin to detect and log unauthorized access attempts.
A Flask-based honeypot that mimics Outlook Web Access to detect and log authentication attempts.
A security incident response card game that trains defenders through fictional scenarios and activity-based gameplay.
A Heroku-based web honeypot for creating and monitoring fake HTTP endpoints (honeytokens) to detect attackers and malicious activity.
Open-source tools for creating realistic-behaving electric grid honeynets to detect and analyze cyber threats.
A proof-of-concept tool to externally detect Kippo SSH honeypot instances.
A honeypot that mimics Drupal CMS to detect and log malicious scanning and attack attempts.
A Python-based NTP honeypot that logs NTP scan attempts and DDoS reconnaissance into Redis for security monitoring.
Bash and Python scripts that listen on unused ports and automatically blacklist IPs that connect to them.
A decentralized AI security mesh that provides collective defense, where threat detection on any node protects all nodes within 30 seconds.
A Kubernetes API honeypot with multi-protocol emulation and active defense capabilities for detecting malicious infrastructure attacks.
A simple Docker honeypot server that emulates parts of the Docker HTTP API to detect and log reconnaissance and container creation attempts.
An online repository of Exabeam's security detection content, including data sources, use cases, and rules based on the Common Information Model 2.0.
A low-interaction honeypot that detects exploitation attempts targeting the CVE-2017-10271 WebLogic remote code execution vulnerability.
A honeypot that mimics a vulnerable file upload endpoint to detect and collect malicious uploads.
A hybrid AI honeypot for detecting and interacting with mass web application exploitation attempts.
A high-interaction honeypot for HTTP/HTTPS that emulates vulnerable web applications to observe attacker behavior.
A honeypot that emulates HL7/FHIR healthcare data interfaces to detect and log unauthorized access attempts.
A multithreaded YARA scanner that applies many rules to many files for incident response and malware analysis.
A network security honeypot designed to detect and analyze malicious activity as featured in Applied Network Security Monitoring.
A script to detect and remove Thinkst Canarytokens from files using signature-based detection.
A Python honeyclient for detecting malicious web content through client-side emulation and analysis.
A low-interaction Python honeypot that mimics vulnerable services to detect and log intrusion attempts.
A Python-based Elasticsearch honeypot that detects and analyzes attacks exploiting the CVE-2015-1427 Groovy vulnerability.
A curated collection of resources for Splunk Enterprise Security, including documentation, training, and integration tools.
A printer honeypot proof-of-concept that simulates network printers to detect and analyze unauthorized access attempts.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.