
Log4j-Vulnerability
Educational analysis of the Log4Shell (CVE-2021-44228) vulnerability, detailing its exploitation in a cryptocurrency mining campaign with IoCs, MITRE…

Educational analysis of the Log4Shell (CVE-2021-44228) vulnerability, detailing its exploitation in a cryptocurrency mining campaign with IoCs, MITRE…

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…

Trust & Safety tools for working together to fight digital harms.

Clusters and elements to attach to MISP events or attributes (like threat actors)

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

ThePhish: an automated phishing email analysis tool

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

A tool for simplifying the process of researching IOCs.

Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Defense Against the Shai-Hulud Supply Chain Attack

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…