
fingerprint
Monitoring Registry and File Changes in Windows

Monitoring Registry and File Changes in Windows

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

IoCs and YARA rules from Threatray's Threat Research

A powerful and flexible tool to apply active attacks for disrupting stegomalware

Indicator of Compromise Scanner for CVE-2019-19781

Just my findings of malwares

A portable C# utility for enumerating local and remote windows sessions

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

OpenIOC rules to facilitate hunting for indicators of compromise

Detects attempts and successful exploitation of CVE-2022-26809

Bash tool used for proactive detection of malicious activity on macOS systems.

Portable security rules for the action boundary of AI agents

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

Welcome to the NCC Group Threat Intelligence Alert repo, here you will find the alerts which we have raised to our customers regarding intelligence…