
awesome-industrial-control-system-security
A curated list of resources related to Industrial Control System (ICS) security.

A curated list of resources related to Industrial Control System (ICS) security.

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Signatures and IoCs from public Volexity blog posts.

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.

Collection of private Yara rules.

Curated collection of detection rules and IOCs extracted from DFIR engagements and malware analyses to support threat hunting, incident response, and…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Yara Rules for Modern Malware

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Public repository of Sigma and YARA rules created by Synacktiv

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Detection of Linux Malware C2 RedXOR - demonstration

A Zeek based Agent Tesla malware C2 detector.

A Zeek protocol analyzer for the Facefish rootkit, based on Spicy.

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

A complete Blue Team Cybersecurity Lab featuring pfSense, Suricata, and ELK Stack for network monitoring and threat detection.