
HAFNIUM-IOC
A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Indicator of Compromise Scanner for CVE-2019-19781

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Indicator of Compromise Scanner for CVE-2019-19781

Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

Public repository of Sigma and YARA rules created by Synacktiv

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Collection of YARA signatures from individual research

Fingerprint SSH clients and servers.


A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…

A simple bash script to check for evidence of compromise related to CVE-2024-3400