
ioccheck
A tool for simplifying the process of researching IOCs.

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Static analysis of malicious Python code


PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

This Repository Talks about the Follina MSDT from Defender Perspective

Black-box vulnerability scanner and indicator-of-compromise analyzer for CVE-2020-6287 (RECON) in SAP NetWeaver Java applications, enabling rapid…

Defense Against the Shai-Hulud Supply Chain Attack

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Kalim backdooe Malware Report

Comprehensive analysis of CVE-2022-30190 (Follina MSDT vulnerability) with IOCs, detection rules for SIEMs/EDR, YARA signatures, mitigation scripts,…

CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Clusters and elements to attach to MISP events or attributes (like threat actors)

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.