6-day longest streak
-
santamon ★ PINNED
Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.
Go ★ 113 6mo agoExplain → -
galah ★ PINNED
Galah: An LLM-powered web honeypot.
Go ★ 650 11mo agoExplain → -
venator ★ PINNED ⑂
A flexible detection platform that simplifies rule management and deployment with K8s CronJob and Helm. Venator is flexible enough to run standalone or with other job schedulers like Nomad.
★ 3 1y agoExplain → -
finch ★ PINNED
Fingerprint-aware TLS reverse proxy. Use Finch to outsmart bad traffic—collect client fingerprints (JA3, JA4 +QUIC, JA4H, HTTP/2) and act on them: block, reroute, tarpit, or deceive in real time.
Go ★ 299 6mo agoExplain → -
bumblebee ★ PINNED ⑂
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
Go ★ 1 25d agoExplain → -
awesome-threat-detection ★ PINNED
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
★ 4.7k 5mo agoExplain → -
awesome-oscp
A curated list of awesome OSCP resources
★ 3.4k 2y agoExplain → -
fatt
FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic
Python ★ 684 2y agoExplain → -
burpa
Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application Security Testing (DAST).
Python ★ 536 8y agoExplain → -
honeyLambda
honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS Lambda and Amazon API Gateway
Python ★ 526 7y agoExplain → -
detection-and-response-pipeline
✨ A compilation of suggested tools/services for each component in a detection and response pipeline, along with real-world examples. The purpose is to create a reference hub for designing effective threat detection and response pipelines. 👷 🏗
★ 295 2y agoExplain → -
deception-as-detection
Deception based detection techniques mapped to the MITRE’s ATT&CK framework
★ 290 8y agoExplain → -
honeybits ▣
A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward your honeypots
Go ★ 277 7y agoExplain → -
salt-scanner ▣
Linux vulnerability scanner based on Salt Open and Vulners audit API, with Slack notifications and JIRA integration
Python ★ 262 8y agoExplain → -
airt
AIRT — A free, open-source AI Red Teaming course with 8 modules and hands-on Docker labs. Built with Perplexity Computer.
HTML ★ 204 3mo agoExplain → -
honeyku ▣
A Heroku-based web honeypot that can be used to create and monitor fake HTTP endpoints (i.e. honeytokens).
Python ★ 65 7y agoExplain → -
hassh-utils
hassh-utils: Nmap NSE Script and Docker image for HASSH - the SSH client/server fingerprinting method (https://github.com/salesforce/hassh)
Lua ★ 58 1y agoExplain → -
honeybits-win ▣
Windows version of honeybits - a PoC tool to create breadcrumbs and honeytokens, to lead the attackers to your honeypots!
Go ★ 24 9y agoExplain → -
quick
QUICk - a go library based on gopacket for analyzing QUIC CHLO messages
Go ★ 21 6y agoExplain → -
Presentations
Some of the presentations given by me
★ 19 10mo agoExplain → -
endpoint-ai-agent-abuse
EAA is a curated catalog of techniques for abusing local AI agents, especially coding agents, through their runtime, configuration, state, tools, and inherited authority.
Python ★ 13 3d agoExplain → -
cve-2024-6387_hassh
HASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).
Python ★ 10 2y agoExplain → -
honeypot-data
🍯 Public honeypot datasets containing HTTP and TLS fingerprint data
★ 10 7mo agoExplain → -
awesome-honeypots ⑂
an awesome list of honeypot resources
Python ★ 10 9y agoExplain → -
cowrie ⑂
Cowrie SSH/Telnet Honeypot
Python ★ 4 7y agoExplain → -
Notes ⑂
No description.
★ 4 6y agoExplain → -
fingerproxy ⑂
Fingerproxy is an HTTPS reverse proxy. It creates JA3, JA4, Akamai HTTP2 fingerprints, and forwards to backend via HTTP request headers.
Go ★ 2 10mo agoExplain → -
0x4d31.github.io
No description.
HTML ★ 2 6y agoExplain → -
hassh ⑂
HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be easily stored, searched and shared in the form of a small MD5 fingerprint.
Python ★ 2 7y agoExplain → -
glutton ⑂
Generic Low Interaction Honeypot
Go ★ 1 1y agoExplain → -
eql ⑂
No description.
★ 1 6y agoExplain → -
ja3 ⑂
JA3 is a standard for creating SSL client fingerprints in an easy to produce and shareable way.
★ 1 6y agoExplain → -
rdfp ⑂
No description.
★ 1 6y agoExplain → -
checkpot ⑂
Checkpot Honeypot Checker
Python ★ 1 7y agoExplain → -
mitmproxy ⑂
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
★ 0 10mo agoExplain → -
ja4 ⑂
JA4+ is a suite of network fingerprinting standards
★ 0 1y agoExplain → -
gopacket ⑂
Provides packet processing capabilities for Go
Go ★ 0 7y agoExplain → -
cryptoAUS_honeytoken_workshop
CryptoAUS Honeytoken Workshop
JavaScript ★ 0 9y agoExplain →
No repos match these filters.