
HAFNIUM-IOC
A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Extracts selected MISP attributes, including IP addresses, URLs, and hashes, into reusable output files.

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…



Sophos-originated indicators-of-compromise from published reports

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

Signatures and IoCs from public Volexity blog posts.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…


This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

Scan files or process memory for CobaltStrike beacons and parse their configuration

This repository contains indicators of compromise (IOCs) of our various investigations.

Python library for extracting Indicators of Compromise, URLs, IP addresses, hashes, and email addresses from text using declarative grammars instead…