
MOVEit-CVE-2023-34362
This repository investigates the exploitation of CVE-2023-34362 in the MOVEit file transfer server by the TA505 (Cl0p) ransomware group. It explores…

This repository investigates the exploitation of CVE-2023-34362 in the MOVEit file transfer server by the TA505 (Cl0p) ransomware group. It explores…

OS-level runtime auditing for unpredictable automation.

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.

CarbonBlack hunting queries to detect PrintNightmare (CVE-2021-1675) exploitation via file, module load, and process events, based on Sigma rules.

Layered detection toolkit for CVE-2026-31431 (Copy Fail) Linux kernel LPE. Provides eBPF, auditd, Sigma rules, page-cache diff, and IOC guides for…

Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation

Incident Response - Fast suspicious file finder

Wazuh SCA Linux hardening policy for Copy Fail (CVE-2026-31431)

OS-level monitor for AI agents: observes processes, file access, and network activity on the local machine and attributes each event to an agent…

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and generates…

Selective protocol extractor from PCAPs or interfaces

A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…

Created to help detect IOCs for CVE-2022-21894: The BlackLotus campaign

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

A binary and file access authorization system for macOS.