Lightweight, local-first memory for AI agents. Hybrid vector + BM25 search, LLM-powered fact extraction, zero infrastructure — just pip install.
-
Updated
Apr 2, 2026 - Python
Lightweight, local-first memory for AI agents. Hybrid vector + BM25 search, LLM-powered fact extraction, zero infrastructure — just pip install.
C2 server fingerprinter — Cobalt Strike, Sliver, Mythic, Havoc, Brute Ratel
DISA STIG checker + NIST 800-53 RMF mapper + POAM emitter
MCP server hardening linter — capability declarations, transport, tool descriptions
Re-identification risk assessment that computes k-anonymity, l-diversity, and HIPAA Safe Harbor compliance on a dataset.
Generate a CycloneDX SBOM directly from an unpacked firmware root filesystem and flag components with known CVEs and EOL kernels.
Diff two firmware images and surface exactly what changed: new binaries, flipped config flags, added certs, and shifted entropy regions.
Sniff and decode BLE GATT traffic, fingerprint device profiles, and assert on insecure pairing/characteristics in CI against a capture.
DISA STIG-aligned osquery configs + RMF mapper
Scan firmware blobs and filesystem dumps for hardcoded private keys, API tokens, default creds, and weak RSA/ECC material.
Audit UEFI firmware dumps for missing Secure Boot keys, unsigned modules, S3 boot-script vulns, and known SMM threats.
AIS vessel tracking & sanctions-evasion anomaly detection
Validate OTA update packages end-to-end: signature chains, rollback protection, anti-downgrade counters, and delta-patch integrity.
Spin up a high-interaction Modbus/DNP3 ICS honeypot that logs attacker register reads/writes as structured JSON.
Model your sales pipeline as a YAML state machine and compute conversion rates, stage velocity, and weighted forecast straight from CRM exports.
Replay, fuzz, and assert on CAN bus traffic from a .pcap or SocketCAN interface with a tiny YAML DSL.
Summarize flows/talkers/protocols from a pcap text export
Self-hosted password cracking queue — multi-user hashcat with audit log
Self-hosted, zero-telemetry anti-fingerprint privacy container with a built-in attribution/leak self-audit
Counter-UAS telemetry/log analyzer that flags drone-detection events, RF bands, and track anomalies.
Add a description, image, and links to the cognis topic page so that developers can more easily learn about it.
To associate your repository with the cognis topic, visit your repo's landing page and select "manage topics."