
akamai-security-research
This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…


TAXII server implementation in Python from EclecticIQ

Fingerprint SSH clients and servers.

Python Decoders for Common Remote Access Trojans

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

ioc2rpz is a place where threat intelligence meets DNS.

Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs

Extract useful information from PANOS support file for CVE-2024-3400



Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…