Showing 36 of 129 projects
A PowerShell module for interacting with VirusTotal's API to analyze suspicious files, URLs, domains, and IP addresses.
An open-source repository of cybersecurity detection rules and threat identifiers for security teams to enhance threat detection capabilities.
A practical classroom course suite teaching cyber defense monitoring using Suricata and Arkime for threat detection and packet analysis.
A honeypot that emulates USB storage devices to detect and capture malware that spreads via USB propagation.
A tool for Exchange administrators to detect malicious client-side rules, VBScript forms, and custom homepages used in attacks.
A honeypot that detects and logs exploitation attempts targeting the Log4Shell vulnerability (CVE-2021-44228).
Kernel-mode malicious activity hooking framework for macOS security analysis and malware research.
A set of Suricata IDS/IPS detection rules specifically designed to identify NMAP port scans across various scan types and speeds.
A Python utility for securely unpacking and staging suspicious files, designed for integration with malware analysis tools like Cuckoo Sandbox.
Analyzes web traffic via Squid proxy to detect command and control servers and malicious sites using Spamhaus data.
A simple and effective honeypot that mimics phpMyAdmin to detect and log unauthorized access attempts.
A Flask-based honeypot that mimics Outlook Web Access to detect and log authentication attempts.
A security incident response card game that trains defenders through fictional scenarios and activity-based gameplay.
A Heroku-based web honeypot for creating and monitoring fake HTTP endpoints (honeytokens) to detect attackers and malicious activity.
Open-source tools for creating realistic-behaving electric grid honeynets to detect and analyze cyber threats.
A proof-of-concept tool to externally detect Kippo SSH honeypot instances.
A honeypot that mimics Drupal CMS to detect and log malicious scanning and attack attempts.
A Python-based NTP honeypot that logs NTP scan attempts and DDoS reconnaissance into Redis for security monitoring.
Bash and Python scripts that listen on unused ports and automatically blacklist IPs that connect to them.
A Kubernetes API honeypot with multi-protocol emulation and active defense capabilities for detecting malicious infrastructure attacks.
A decentralized AI security mesh that provides collective defense, where threat detection on any node protects all nodes within 30 seconds.
A simple Docker honeypot server that emulates parts of the Docker HTTP API to detect and log reconnaissance and container creation attempts.
A low-interaction honeypot that detects exploitation attempts targeting the CVE-2017-10271 WebLogic remote code execution vulnerability.
An online repository of Exabeam's security detection content, including data sources, use cases, and rules based on the Common Information Model 2.0.
A honeypot that mimics a vulnerable file upload endpoint to detect and collect malicious uploads.
A high-interaction honeypot for HTTP/HTTPS that emulates vulnerable web applications to observe attacker behavior.
A multithreaded YARA scanner that applies many rules to many files for incident response and malware analysis.
A hybrid AI honeypot for detecting and interacting with mass web application exploitation attempts.
A honeypot that emulates HL7/FHIR healthcare data interfaces to detect and log unauthorized access attempts.
A script to detect and remove Thinkst Canarytokens from files using signature-based detection.
A Python honeyclient for detecting malicious web content through client-side emulation and analysis.
A network security honeypot designed to detect and analyze malicious activity as featured in Applied Network Security Monitoring.
A Python-based Elasticsearch honeypot that detects and analyzes attacks exploiting the CVE-2015-1427 Groovy vulnerability.
A low-interaction Python honeypot that mimics vulnerable services to detect and log intrusion attempts.
A curated collection of resources for Splunk Enterprise Security, including documentation, training, and integration tools.
A printer honeypot proof-of-concept that simulates network printers to detect and analyze unauthorized access attempts.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.