
reactor
Runs custom filters on Elasticsearch and alerts on matches

Runs custom filters on Elasticsearch and alerts on matches

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228

A simple bash script to check for evidence of compromise related to CVE-2024-3400

A collection of IOCs for CVE-2021-44228 also known as Log4Shell

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

Detect Tactics, Techniques & Combat Threats

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

Galah: An LLM-powered web honeypot.

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

Apache Real Time Logs Analyzer System

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Zeek package for tracking long connections to report them before they have completed.

A Canary which fires when uninstalled

Mapping Corelight or Zeek data to Elastic Common Schema logs