
CVE-2021-31166-detection-rules
Different rules to detect if CVE-2021-31166 is being exploited

Different rules to detect if CVE-2021-31166 is being exploited

A Zeek based STRRAT malware detector.

A Zeek based Agent Tesla malware C2 detector.

A Zeek based Gozi banking malware detector.

Zeek detection for CVE-2020-16898-"Bad Neighbor"

Some files for red team/blue team investigations into CVE-2021-44228

Detects CVE-2020-16898: "Bad Neighbor"

CitrixBleed 2 NetScaler honeypot logs

Web-based Traffic and Cybersecurity Network Traffic Monitoring

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

ZoneMinder is a free, open source Closed-circuit television software application developed for Linux which supports IP, USB and Analog cameras.

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Canarytokens helps track activity and actions on your network

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring,…

Hunts for potential malware downloads and suspicious domain calls via common Windows LOLBins using YARA rules and Nexthink telemetry modules.

Signatures and IoCs from public Volexity blog posts.