
ZeroLogon-Exploitation-Check
quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…

CVE-2020-9483 OR CVE-2020-13921

CVE-2016-4999

create cypher create statements for neo4j out of netstat files from multiple machines



Check for events that indicate non compatible devices -> CVE-2020-1472


This script checks the Citrix Netscaler if it has been compromised by CVE-2019-19781 attacks and collects all file system information

Express security essentials deployment for Linux Servers

A Bro package to identify connections that are bursting (lots of data and transferring quickly).

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Zabbix Template to monitor for Windows Event Viewer event's related to Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472. Monitors event…


Top DNS Measurement for Bro

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.