
ESXi_ransomware_bitcoinWallets
ESXi semi-automated ransomware attacks bitcoin wallets

ESXi semi-automated ransomware attacks bitcoin wallets

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Apache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon…

This repository contains indicators of compromise (IOCs) of our various investigations.

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

HexaLocker ransomware analysis