
sorry-ransomware-analysis
Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation

Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065

Scanner de IOCs del ataque de cadena de suministro TeamPCP (CVE-2026-33634).

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Open-source security orchestration, automation, and response (SOAR) platform with a visual workflow editor, prebuilt security app integrations, and…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Curated public database of indicators of compromise aggregated by Wiz Research for threat detection, hunting, and incident response workflows.

Curated collection of indicators of compromise extracted from real-world malware investigations, including hashes, domains, and IPs for threat…

Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…

Just my findings of malwares

Collects and organizes malware indicators of compromise (IOCs) for rapid threat detection, incident response, and actionable intelligence sharing.

This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports

Curated collection of detection rules and IOCs extracted from DFIR engagements and malware analyses to support threat hunting, incident response, and…

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.


Curated repository of documented firmware supply chain attacks, featuring IoCs, detection tools, and references to help defenders understand and…

Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints