
CVE-2021-42292
Zeek package detecting CVE-2021-42292 Microsoft Excel local privilege escalation exploit via network traffic analysis of spreadsheet downloads.

Zeek package detecting CVE-2021-42292 Microsoft Excel local privilege escalation exploit via network traffic analysis of spreadsheet downloads.

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

Github mirror of official Kismet repository

Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

A repository of my own Sigma detection rules.

A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.

Curated repository of Indicators of Compromise (IOCs), attack source IPs, and Snort/Suricata detection rules for Log4Shell (CVE-2021-44228) attacks.

A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.

Public repository of Sigma and YARA rules created by Synacktiv

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228

A simple bash script to check for evidence of compromise related to CVE-2024-3400

Zeek package to detect exploitation attempts of CVE-2017-2741 targeting HP JetDirect printers via network traffic analysis.

A collection of IOCs for CVE-2021-44228 also known as Log4Shell