


Signatures and IoCs from public Volexity blog posts.

Sophos-originated indicators-of-compromise from published reports

Python library for extracting Indicators of Compromise, URLs, IP addresses, hashes, and email addresses from text using declarative grammars instead…

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional…

TAXII server implementation in Python from EclecticIQ

Fingerprint SSH clients and servers.

Suspicious DGA from PDNS and Sandbox.


A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…

Indicators of Compromise from Amnesty International's cyber investigations

Repo containing all info, scripts, etc. related to CVE-2021-44228

Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs

IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE…

Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and…

Extract useful information from PANOS support file for CVE-2024-3400