
fortileak-01-2025-Be
Repository documenting the Fortigate firewall vulnerability CVE-2022-40684 and publicly disclosed affected data for security research and defensive…

Repository documenting the Fortigate firewall vulnerability CVE-2022-40684 and publicly disclosed affected data for security research and defensive…

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Automated observable analysis engine for threat intelligence, digital forensics, and incident response, integrating with diverse analyzers via a…

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Automated vulnerability scanner for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass) with TLS certificate enumeration, authentication…

ML-powered threat hunting dashboard that automates external asset discovery, enriches data via Shodan and NVD, and prioritizes risks using ensemble…

Low to medium interaction honeypot for emulating UDP/TCP services, logging attacker activity, and posting threat data to HoneyDB and Twitter.…

Read-only WordPress User Registration CVE-2026-1492 checker for hidden admins, plugin version, uploads PHP, cron, and compromise IOCs.

Lightweight investigation notebook for tracking threat intelligence, indicators of compromise (IOCs), and managing security incident response…

KQL hunting query for Microsoft Defender for Endpoint to detect WinRAR file extension spoofing (CVE-2023-38831) using IOCs and file event analysis.

Read-only post-exploitation credential hunter that surfaces reusable passwords, keys, hashes, and credential files across Windows and Linux hosts…

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Shodan Monitoring integration for TheHive.

Threat hunting command system for agentic IDEs

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

Centralized threat hunting platform that aggregates investigation data, caches API responses, and enables team collaboration with integrated CLI…

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)