
sorry-ransomware-analysis
Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

This repository contains indicators of compromise (IOCs) of our various investigations.

ESXi semi-automated ransomware attacks bitcoin wallets

HexaLocker ransomware analysis

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

Apache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack