
NetScope
Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

Some files for red team/blue team investigations into CVE-2021-44228

Windows honeypot using ProjFS to project decoy files that trigger Event Log and desktop alerts when accessed, with SMB remote session logging for…

Experimental Decoy Broker

ML-Based behavioral endpoint detection system for Linux machines

Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write

A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…


Signatures and IoCs from public Volexity blog posts.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs


Public repository of Sigma and YARA rules created by Synacktiv

Honeypot for CVE-2025-53770 aka ToolShell

cve-2025-8088_detection

Sigma-Rule-for-CVE-2021-40438-Attack-Attemp

A simple bash script to check for evidence of compromise related to CVE-2024-3400