Agentic AI EDR for developer workstations and autonomous agent swarms. Build Swarm Detection & Response platforms with Clawdstrike.
-
Updated
Sep 21, 2026 - TypeScript
Agentic AI EDR for developer workstations and autonomous agent swarms. Build Swarm Detection & Response platforms with Clawdstrike.
A cybersecurity game in Azure Data Explorer
Comprehensive SOC Analyst notes covering incident response, threat hunting, SOC workflows, and cybersecurity concepts—perfect for exam prep and skill-building in blue team operations.
Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help detect real-world adversary behaviors in their environments.
Self-hosted PCAP analysis platform with LLM-powered incident triage, signature-based threat detection, and AI-generated incident narratives. Features network change monitoring across captures, deep packet inspection via nDPI, and automated Wireshark filter generation. Runs fully offline with local LLMs (Ollama, LM Studio).
Highly customizable low-interaction experimental honeypot that mimics specific hosts.
Harnessing AI to Disrupt and Evaluate Security (HADES)
CLI-based 802.11 Rogue (Fake) AP & Hidden AP Spotter
هذا المشروع يحتوي على جميع الدروس والموارد لكورس تعلم الأمن السيبراني من إعداد Coder Shiyar. مناسب للمبتدئين ومن يريدون تحسين مهاراتهم في الأمن السيبراني، اختبار الاختراق، أمان الشبكات، وتقنيات الحماية الأخلاقية.
This repo is all about Blue teamming and CyberDefenders Write-up for their DFIR challenges
An Attentive Graph Agent for Topology-Adaptive Cyber Defence
"Dead1ock-h4ck" is an open-source project dedicated to exploring cybersecurity and ethical hacking techniques. The project aims to provide resources and tools for learning about network security, cryptography, and penetration testing.
Production-validated detection queries and hunting artifacts across 9 platforms (KQL, Sigma, Splunk, Athena, PowerShell, Velociraptor, YARA, Suricata, osquery). Each with triggers, false positives, tuning guidance, and validation steps.
Digital forensic (DFIR) specialist roadmap.
Hybrid LSTM-Markov attack chain forecasting for MITRE ATT&CK. Learns from 4,849 campaign chains + 8,437 real intrusion traces. Generates 26,051 risk-ranked multi-step attack futures via constrained beam search. 86% next-step accuracy, 0.76 Pearson correlation with NCISS severity. SECRYPT 2026 submission.
OpenMTD - A framework for efficient MTD evaluation
An open-source JSON-Schema validator test suite and command-line tool for OpenC2
This repository provides comprehensive guides, configurations, rules, and practical examples for Snort, the open-source intrusion detection system (IDS). Ideal for cybersecurity professionals and enthusiasts looking to enhance their network security skills.
SENTINEL SOC is a professional-grade Security Operations Center (SOC) dashboard that simulates real-world threat detection, investigation, and response workflows. Built with React and Recharts, it features live alert monitoring, interactive investigation playbooks with terminal-style execution, global attack maps, real-time CVE intelligence🔒.
Proactive AI-driven cyber-physical escalation-aware defense — doctrinal architecture for U.S. cyber defense at machine speed.
To associate your repository with the cyber-defense topic, visit your repo's landing page and select "manage topics."