
ThePhish
ThePhish: an automated phishing email analysis tool

ThePhish: an automated phishing email analysis tool

Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

A Simple Log4j Indicator of Compromise Linux Detector

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…


Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Automated forensic script hunting for cve-2019-19781

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441

Python script to check Palo Alto firewalls for CVE-2024-3400 exploit attempts

Run on your ManageEngine server

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

A simple bash script to check for evidence of compromise related to CVE-2024-3400