
misp-extractor
Extracts selected MISP attributes, including IP addresses, URLs, and hashes, into reusable output files.

Extracts selected MISP attributes, including IP addresses, URLs, and hashes, into reusable output files.

Reverse engineering analysis of StealC Stealer, an info-stealer that uses RuntimeBroker.exe hollowing, C2 infrastructure, and payload extraction.…

Detection scripts, patch checker & hardening guide for CVE-2026-44963 (Veeam B&R RCE)

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

KQL Hunting for WinRAR CVE-2023-38831

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…

CVE-2026-52813 (Gogs Path Traversal → Git Hooks RCE) defensive writeup: root-cause & patch analysis, Sigma/SIEM detection rules, IOCs, non-intrusive…

Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs

Live Feed of C2 servers, tools, and botnets


Extract indicators of compromise from text, including "escaped" ones.

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)

Hardware Sandbox Toolkit

DPS' Lightweight Investigation Notebook

Indicators of Compromise from Amnesty International's cyber investigations

📕NVD Database

Public IOCs about log4j CVE-2021-44228