
timesketch
Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Clusters and elements to attach to MISP events or attributes (like threat actors)

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Rust-based pattern matching engine for malware researchers. Create YARA rules with textual/binary patterns, wildcards, and regex to identify and…

CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

SAP NetWeaver vulnerability and compromise assessment tool that detects CVE-2025-31324/42999, scans for IOCs, analyzes HTTP access and Java trace…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Black-box vulnerability scanner and indicator-of-compromise analyzer for CVE-2020-6287 (RECON) in SAP NetWeaver Java applications, enabling rapid…

Defense Against the Shai-Hulud Supply Chain Attack

Comprehensive analysis of CVE-2022-30190 (Follina MSDT vulnerability) with IOCs, detection rules for SIEMs/EDR, YARA signatures, mitigation scripts,…

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

This Repository Talks about the Follina MSDT from Defender Perspective

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Kalim backdooe Malware Report