
dissect.cobaltstrike
Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Scans Windows systems for PowerShell Empire persistence payloads including scheduled tasks, WMI subscriptions, auto-run entries, and accessibility…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

ToolShell scanner - CVE-2025-53770 and detection information

Lightweight low-interaction network honeypot sensor that captures TCP payloads, performs passive TLS/HTTP/SSH fingerprinting, and outputs structured…

Curated collection of resources for incident response on Log4Shell (CVE-2021-44228, CVE-2021-45046), including threat intel, mitigations, IOCs,…

Zeek package detecting CVE-2021-38647 (OMIGOD) exploit attempts by monitoring OMI/WMI traffic for missing Authorization headers and malicious SOAP…

Multi-layer security framework for AI agent ecosystems. Provides pre-installation skill auditing, file integrity monitoring, runtime protection, and…

PowerShell IOC-hunting script for CVE-2022-47966 that parses ManageEngine HTTP access logs, decodes suspicious SAML payloads, and writes findings to…

Low-interaction honeypot mimicking Cisco FMC web surface to capture unauthenticated Java deserialization probes, extract attacker payloads, and log…

Zeek package that detects CVE-2021-38647 (OMIGOD) exploit attempts by monitoring OMI/WMI traffic for missing Authorization headers and analyzing…

Zeek package detecting CVE-2021-38647 (OMIGOD) exploit attempts by monitoring OMI/WMI traffic for missing Authorization headers and malicious SOAP…

Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)