
gundog
gundog - guided hunting in Microsoft Defender

gundog - guided hunting in Microsoft Defender

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)

A portable C# utility for enumerating local and remote windows sessions

Bash tool used for proactive detection of malicious activity on macOS systems.

Simple IP Information Tools for Reputation Data Analysis

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Basic log analysis tool to detect impossible travel via IP address geographic information

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

KQL Hunting for WinRAR CVE-2023-38831

Find log4j for CVE-2021-44228 on some places * Log4Shell

Read-only WordPress User Registration CVE-2026-1492 checker for hidden admins, plugin version, uploads PHP, cron, and compromise IOCs.

GrayXploit Security research and defensive team validate this toolkit for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass). Includes…

Data we are receiving from our honeypots about CVE-2021-44228
