
threat-research
IoCs and YARA rules from Threatray's Threat Research

IoCs and YARA rules from Threatray's Threat Research

gundog - guided hunting in Microsoft Defender

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)


A portable C# utility for enumerating local and remote windows sessions

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

This is an incident response playbook we created for the Vercel April 2026 compromise


Simple IP Information Tools for Reputation Data Analysis

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery…

ToolShell scanner - CVE-2025-53770 and detection information

Basic log analysis tool to detect impossible travel via IP address geographic information

Centralized IoC scanner that deploys Loki across endpoints, collects detection results, and parses logs into CSV for incident response and forensic…

Spip network sensor written in Go

Perform file-based malware scan on your on-prem servers with AWS


A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.