
Raccine
A Simple Ransomware Vaccine

A Simple Ransomware Vaccine

A script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".

A simple bash script to check for evidence of compromise related to CVE-2024-3400

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

Simple webhook to block exploitation of CVE-2022-0811

Zeek script to detect servers vulnerable to CVE-2020-13777

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

🐍 High-performance, multi-threaded YARA & IOC scanner

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring,…

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

YARA signature and IOC database for my scanners and tools

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

Detects shadow-administrator accounts in WordPress via configurable indicators and heuristics, then removes selected accounts through guarded, logged…

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

SQL powered operating system instrumentation, monitoring, and analytics.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…
