
ncentral-compromise-ioc-triage
Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints

Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints

CVE-2023-34362-IOCs. More information on Deep Instinct's blog site.

Run on your ManageEngine server

React2shell-web-scanner

HexaLocker ransomware analysis

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

cve-2025-8088_detection

Honeypot for CVE-2025-53770 aka ToolShell

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

A tool for simplifying the process of researching IOCs.


Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

Sophos-originated indicators-of-compromise from published reports


Indicators of Compromise from Amnesty International's cyber investigations

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.