
CYBERDUDEBIVASH-Cisco-AsyncOS-CVE-2025-20393-Scanner
This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

TIH is an intelligence tool that helps you in searching for IOCs across multiple openly available security feeds and some well known APIs. The idea…

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

No longer maintained. Please refer to Google Threat Intelligence / Virus Total collections.

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

WinDbg plugin for automated malware dynamic analysis and IOC extraction. Executes within the debugger to collect predefined indicators and writes…

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

IOCPARSER.COM is a Fast and Reliable service that enables you to extract IOCs and intelligence from different data sources.

IOCs and notes related to malware