
cms-exploitation-campaign
Large Scale Exploitation Campaign against CMS devices reported in July 2026

Large Scale Exploitation Campaign against CMS devices reported in July 2026

Wazuh detection rules for CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite, monitoring web access logs and zimbra.log for…

Lightweight network intrusion detection engine capturing live traffic with libpcap. Detects SYN/ICMP floods, port scans, and signature-based web…

Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server…

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Self-hostable AI SOC that fuses security alerts, auto-triages via agentic AI, runs MITRE ATT&CK investigations, and logs every agent decision in a…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

AV/EDR Lab environment setup references to help in Malware development

This project is a SIEM with SIRP and Threat Intel, all in one.

An ADCS honeypot to catch attackers in your internal network.

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Blue Team detection lab created with Terraform and Ansible in Azure.

Network anomaly detector that monitors raw packets to identify port scanning activity in real time, with flexible sniffing duration controls and live…

A tool for malicious behavior detection in IoT devices

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.