
Noriben
Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…

Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

A Simple Log4j Indicator of Compromise Linux Detector

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…


Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Run on your ManageEngine server

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441

Python script to check Palo Alto firewalls for CVE-2024-3400 exploit attempts

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

A simple bash script to check for evidence of compromise related to CVE-2024-3400

Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819