
ioc
A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

Collection of private Yara rules.

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

A collection of IOCs for CVE-2021-44228 also known as Log4Shell

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, Suricata and…


Yara Rules for Modern Malware

A repository to release detection rules to the public

Sigma Rule for CVE-2025-49666

A repository of sysmon configuration modules

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Detects attempts and successful exploitation of CVE-2022-26809

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Public repository of Sigma and YARA rules created by Synacktiv

Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750