CuraSec

tag: Tooling · 8 items

  • Engineer — Learn: If YARA-X is part of your CI/CD or scanning pipeline, this routine release adds incremental improvements worth reviewing before your next scheduled upgrade — no urgent action required.
  • SOC/IR — Learn: Teams using YARA-X for threat hunting or malware triage should note the new release; check the changelog for any detection-relevant engine improvements before updating in a hunting workflow.
  • Leader — Skip
2026-08-28 · GitHub Trending · source ↗ #ai-security#prompt-injection#tooling
  • Engineer — Learn: New read-only plugin worth evaluating if DeepSeek Harness is in your AI pipeline; covers prompt-injection detection and local config audit, but adoption is nascent (51 stars) with no enrichment signals to pressure a faster decision.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-28 · GitHub Trending · source ↗ #ai-security#penetration-testing#tooling
  • Engineer — Learn: An early-stage AI agent framework for automated recon-to-report pentesting; worth evaluating as a complement to manual AppSec workflows, but no immediate change to running systems required.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-26 · GitHub Trending · source ↗ #windows-hardening#tooling#audit
  • Engineer — Learn: A C#/.NET 4.8 toolkit for auditing and reversibly hardening Windows hosts is worth a quick evaluation for teams managing Windows endpoints or servers, but with only 51 stars and no enrichment signals, vet it before adoption in any production pipeline.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-14 · GitHub Trending · source ↗ #ai-security#tooling#devsecops
  • Engineer — Learn: A linting and security audit tool for AI agent skill definitions worth evaluating if your team is building or vetting agent-based workflows on Claude/Cursor/Codex.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-24 · GitHub Trending · source ↗ #ai-security#tooling#resources
  • Engineer — Learn: A community-curated tool list may surface defensive AI/LLM security tooling worth evaluating, but requires no immediate action on running systems.
  • SOC/IR — Learn: Browsing the offensive and detection tooling sections could expand the team’s awareness of attacker capabilities and new hunt tooling to evaluate.
  • Leader — Skip
  • Engineer — Learn: An open-source AI agent orchestration tool aimed at automated code vulnerability discovery — worth evaluating for AppSec pipelines, but no exploitation pressure or immediate action required.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-15 · SANS ISC · source ↗ #siem#elk-stack#tooling
  • Engineer — Skip
  • SOC/IR — Learn: If you run the DShield SIEM, this update brings ELK 8.19.15 and additional dashboards; evaluate whether to upgrade your instance this quarter.
  • Leader — Skip