#1Tools for collecting, analyzing, and operationalizing threat feeds, indicators of compromise (IOCs), and attack trends.
Kitploit recommended

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

EU focused compliance MCP server

A tool for simplifying the process of researching IOCs.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Automatic security alert response framework by AWS Serverless Application Model

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Tor-based leaked credential search tool that queries the pwndb2 hidden service to find emails and passwords exposed in data breaches, with wildcard…

Dockerized honeypot for CVE-2021-44228.

apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links

Lightweight honeypot for Apache HTTP Server path traversal vulnerability CVE-2021-41773, designed to capture and log exploitation attempts.

Free BACnet/BMS vulnerability scanner for building automation systems. Detects CVE-2026-3611 (CVSS 10.0), CVE-2026-24060, and exposed HVAC/BAS…

List of company advisories log4j

Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

CitrixBleed 2 NetScaler honeypot logs

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

Operational security controls with forensic guarantees