
ToolShellFinder
Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771
digital-forensicsforensicsincident-response+5

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Honeypot for CVE-2025-53770 aka ToolShell

This Repository Talks about the Follina MSDT from Defender Perspective

Microsoft Threat Intelligence Security Tools

KQL detection rules for Microsoft Sentinel and Defender XDR covering the bikini/exploitarium anonymous disclosure — a personal research archive of…

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…