
copy-fail-CVE-2026-31431-IOC
Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation

Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Public repository of Sigma and YARA rules created by Synacktiv

Fingerprint SSH clients and servers.

IOC feed and analysis toolkit for EITest campaigns, featuring C2 data decryption, victim payload decoding, and sinkhole log processing for threat…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and…

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Extract useful information from PANOS support file for CVE-2024-3400

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

Python-based scanner for CVE-2025-31324 that identifies vulnerable SAP NetWeaver Visual Composer instances and detects indicators of compromise from…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Contains a simple yara rule to hunt for possible compromised KeePass config files

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065