


Open-source security orchestration, automation, and response (SOAR) platform with a visual workflow editor, prebuilt security app integrations, and…

A continuously updated resource that catalogs confirmed data breaches from across the globe. Each entry includes the breach name, usually aligned…

Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.


Elastic Security Labs releases

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

IoCs and YARA rules from Threatray's Threat Research

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

YARA signature and IOC database for my scanners and tools

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project