
timesketch
Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Clusters and elements to attach to MISP events or attributes (like threat actors)


CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Defense Against the Shai-Hulud Supply Chain Attack

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

Kalim backdooe Malware Report

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

TIH is an intelligence tool that helps you in searching for IOCs across multiple openly available security feeds and some well known APIs. The idea…

Static analysis of malicious Python code

A tool for studying JavaScript malware.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…