
mini-shai-hulud-scanner
Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Bash script to detect CVE-2025-55182 (React2Shell) and credential exposure in Next.js projects. Zero dependencies.

Recognizing the most likely APT groups responsible for an incident

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…


Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and…

SOARCA - The Open Source CACAO-based Security Orchestrator!

Honeypot for CVE-2025-53770 aka ToolShell

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

Repository containing the compromised certificate seen in recent CVE-2022-30190 (Follina) attacks.

This repository contains Yara rule and the method that a security investigator may want to use for CVE-2022-26134 threat hunting on their Linux…

Contains a simple yara rule to hunt for possible compromised KeePass config files

Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

Threat-Informed Detection & Mitigation Package for MOVEit Transfer Vulnerability



IOCs for CVE-2019-19781

CVE-2022-28672 Vulnerabilidad Foxit PDF Reader - UaF - RCE - JIT Spraying