
notepadpp-supply-chain-iocs
IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.


A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

Python-based scanner for CVE-2025-55182 indicators of compromise. Checks filesystem paths, processes, systemd services, cron persistence, and…


Advanced SMB Honeypot: CVE-2025-33073 Research & Implementation


APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

This is a repo for fetching Applocker event log by parsing the win-event log

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

Rapidly Search and Hunt through Windows Forensic Artefacts

Structured collection of 500+ Hack The Box machine writeups, 400+ challenge solutions, and interactive learning tools including knowledge graphs,…

Step-by-step walkthrough of a LetsDefend SOC342 lab analyzing CVE-2025-53770 SharePoint ToolShell auth bypass and RCE, including attack chain,…

Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Kernel-level security & attack response for Linux servers.