
rustinel
Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

IoCs and YARA rules from Threatray's Threat Research

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Some of my KQL hunting queries


An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

Spip network sensor written in Go


AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Aggregate, filter, and track CVEs from multiple sources with team collaboration, custom dashboards, alerts, and AI-powered analysis for vulnerability…

This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Curated public database of indicators of compromise aggregated by Wiz Research for threat detection, hunting, and incident response workflows.

Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

A centralized and enhanced memory analysis platform