
amcache-evilhunter
Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…

IoCs and YARA rules from Threatray's Threat Research

Indicator of Compromise Scanner for CVE-2019-19781

A portable C# utility for enumerating local and remote windows sessions

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

OpenIOC rules to facilitate hunting for indicators of compromise

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery…

Centralized IoC scanner that deploys Loki across endpoints, collects detection results, and parses logs into CSV for incident response and forensic…

Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.