
msticpy
Microsoft Threat Intelligence Security Tools
anomaly-detectioncloud-securityeducation+6

Microsoft Threat Intelligence Security Tools

KQL detection rules for Microsoft Sentinel and Defender XDR covering the bikini/exploitarium anonymous disclosure — a personal research archive of…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Honeypot for CVE-2025-53770 aka ToolShell

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

This Repository Talks about the Follina MSDT from Defender Perspective

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…