
CVE-2020-16899
CVE-2020-16899 - Microsoft Windows TCP/IP Vulnerability Detection Logic and Rule

CVE-2020-16899 - Microsoft Windows TCP/IP Vulnerability Detection Logic and Rule

MysqlHoneypot

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…


Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

YARA signature and IOC database for my scanners and tools

TrustedSec Sysinternals Sysmon Community Guide

AV/EDR Lab environment setup references to help in Malware development

Rules generated from our investigations.

Zeek Log Cheatsheets

Sigma rules from Joe Security

Some Threat Hunting queries useful for blue teamers

Sigma rules to share with the community