
PersistenceSniper
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

Shell script to detect the CVE-2024-3094 backdoor in XZ Utils by checking for malicious code in liblzma build artifacts and identifying affected…

Powershell Empire Persistence finder

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

Shell-based scanner to detect the XZ Backdoor (CVE-2024-3094) vulnerability in files and directories, enabling rapid identification and mitigation of…

Regla YARA para detectar el backdoor de liblzma en XZ Utils 5.6.0/5.6.1 (CVE-2024-3094).

Shell scripts to detect CVE-2024-3094 backdoor in liblzma5 across Kubernetes pods and Docker containers, with SBOM generation via Trivy for…

Scan for files containing the signature from the `xz` backdoor (CVE-2024-3094)

TryHackMe SOC Level 1 — Follina CVE-2022-30190, Nim C2, Chisel, PrintSpoofer, backdoor accounts

PowerShell-based backdoor detection tool for VMware Horizon connection servers, targeting CVE-2021-44228. Includes canary with optional submission…

Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)

Investigation into the XZ Utils backdoor (CVE-2024-3094): chronology, attack chain, risk to SSH, and supply-chain insights. Includes slides, sources,…

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies

Ansible playbooks designed to check and remediate CVE-2024-3094 (XZ Backdoor)

Security analysis project: Real-world CVE breakdown