
misp-galaxy
Clusters and elements to attach to MISP events or attributes (like threat actors)

Clusters and elements to attach to MISP events or attributes (like threat actors)

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

Comprehensive analysis of CVE-2022-30190 (Follina MSDT vulnerability) with IOCs, detection rules for SIEMs/EDR, YARA signatures, mitigation scripts,…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

ThePhish: an automated phishing email analysis tool

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.


Static analysis of malicious Python code

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Kalim backdooe Malware Report

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.