Skip to content
#

kill-chain

Here are 17 public repositories matching this topic...

Autonomous open-source security agent for Linux (Apache-2.0). 40 eBPF hooks, 49 detectors, 47 correlation rules, 65 MITRE ATT&CK techniques, AI triage, behavioral DNA cross-IP tracking, mesh defense.

  • Updated Apr 9, 2026
  • Rust
rt-kcsm

Real-Time Detection of Multi-Stage Attacks using Kill Chain State Machines: Detect multi-stage attacks by correlating alerts from Intrusion Detection Systems (IDS) to generate scenario graphs. By prioritising alerts based on the kill chain model the RT-KCSM reduces false-positive alerts.

  • Updated Apr 8, 2026
  • Jupyter Notebook

MCADDF - A holistic operational framework bridging the gap between on-prem Active Directory and Cloud-native (Entra ID/Azure) security. This repository provides a structured library of verified attack vectors and detection logic, organized via the SERVTEP ID system and mapped to the current MITRE ATT&CK landscape. Curated by Pchelnikau Artur.

  • Updated Mar 2, 2026

Python CLI that ingests alerts from CSV, Splunk, or Elasticsearch; enriches source IPs via VirusTotal and Shodan; scores priority with a 6-factor weighted model; detects correlated incidents and MITRE ATT&CK kill chains; and generates a self-contained HTML analyst report.

  • Updated Apr 6, 2026
  • Python

Improve this page

Add a description, image, and links to the kill-chain topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the kill-chain topic, visit your repo's landing page and select "manage topics."

Learn more