
CVE-2025-32433-Detection
Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Detection of Manjusaka C2 framework

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228

A simple bash script to check for evidence of compromise related to CVE-2024-3400

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Detect Tactics, Techniques & Combat Threats

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

A network packet forensics tool for SSH

Apache Real Time Logs Analyzer System

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

Zeek package for tracking long connections to report them before they have completed.