elk-detection-lab. An ELK environment containing interesting security datasets.
136WASE. The Web Audit Search Engine - Index and Search HTTP Requests and Responses in Web Application Audits with ElasticSearch
115android-nfc-paycardreader. NFC card reader Android app. Currently reads the german GeldKarte and some credit cards.
111Log4Pot. A honeypot for the Log4Shell vulnerability (CVE-2021-44228).
94logstash-linux. Logstash Configuration for Linux Logs (Authentication, Apache, Mail)
92POODLEAttack. PoC implementation of the POODLE attack
70EQUEL. An Elasticsearch QUEry Language
58Burp-SessionAuthTool. Burp plugin which supports in finding privilege escalation vulnerabilities
42sigma-workshop. Elasticsearch/Kibana environment and log data for Sigma workshop
27Clickjacking-Exploit. Clickjacking Proof-of-Concept Exploit
26Burp-MissingScannerChecks. Collection of scanner checks missing in Burp
16NastyWebHackme. Broken web app intentionally built with pentesting obstacles
16mordor. Re-play Adversarial Techniques
10sigma-workshop-operationalization. Workshop "Operationalization of Sigma Rules with Processing Pipelines"
8BrowserCrasher. Crash browsers with opensource test suites
8dfirtrack. DFIRTrack - The Incident Response Tracking Application
7awesome-threat-detection. A curated list of awesome threat detection and hunting resources
7Demo-ClientsideWebAttacks. Demonstration of some client-side web application vulnerabilities (DOM XSS, Clickjacking) and wrong usage of local storage.
7HELK. The Hunting ELK
5CSRF-Multistep. Framework for building multistep CSRF Proof of Concepts
4Burp-Randomizer. Randomize parts of requests with a session handling rule action.
3infosec-notebooks. Jupyter notebooks for threat hunting and incident response
2cycat-taxonomy. CyCAT.org taxonomies
2APTSimulator. A toolset to make a system look as if it was the victim of an APT attack
2postfix-grok-patterns. Logstash configuration and grok patterns for parsing postfix logging
2hashextension. Implementation of the hash extension attack
2evtx2es. Import Windows Eventlogs(.evtx) to ElasticSearch.
1PoodleCheck. A standalone check for the POODLE vulnerability based on the PolarSSL library.
1IntelligentProcessLifecycle. The Intelligent Process Lifecycle of Active Cyber Defenders
1sleepy-puppy. Blind Cross-site Scripting Collector and Manager
1misp-objects. Definition, description and relationship types of MISP objects
1mod0BurpUploadScanner. HTTP file upload scanner for Burp Proxy
1MISP. MISP (core software) - Open Source Threat Intelligence and Sharing Platform (formely known as Malware Information Sharing Platform)
1OwnTwitterFilterBubble. Build your Own Twitter Filter Bubble with Deep Learning
1AVR-RandomStuff. Some tiny programs I coded for Atmel AVR microcontrollers. Sense&pointless, but possibly useful for someone.
1logstash-mail-log. Logstash patterns and config for postfix, cbpolicyd and spamd.
1ImageSearch. Script collection that makes my photos searchable
1testssl.sh. Testing TLS/SSL encryption
1detection-engineering-with-sigma. Detection Engineering with Sigma workshop (2025)
1