
CVE-2021-44228
PowerShell-based backdoor detection tool for VMware Horizon connection servers, targeting CVE-2021-44228. Includes canary with optional submission…

PowerShell-based backdoor detection tool for VMware Horizon connection servers, targeting CVE-2021-44228. Includes canary with optional submission…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection,…

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Small tool to play with IOCs caused by Imageload events

Detection rule validation

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Windows Analysis and Research Toolkit

A binary and file access authorization system for macOS.

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

Automated Network Security with Rust: Detecting and Blocking Port Scanners

A Go library for using zeek broker's websocket API

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Corelight@Home script

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…

Rust tool to detect cell site simulators on an orbic mobile hotspot