
RansomCoinPublic
A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

IoCs and YARA rules from Threatray's Threat Research

Indicator of Compromise Scanner for CVE-2019-19781

OpenIOC rules to facilitate hunting for indicators of compromise


Public repository of Sigma and YARA rules created by Synacktiv



Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

Automated forensic script hunting for cve-2019-19781

Extract useful information from PANOS support file for CVE-2024-3400

Run on your ManageEngine server

IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Repository containing the compromised certificate seen in recent CVE-2022-30190 (Follina) attacks.

This repository contains Yara rule and the method that a security investigator may want to use for CVE-2022-26134 threat hunting on their Linux…

Contains a simple yara rule to hunt for possible compromised KeePass config files