
wp2shell-compromise-scanner-plugin
Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

A simple bash script to check for evidence of compromise related to CVE-2024-3400

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

This repo contains IoCs which are associated with exploitation of CVE-2021-4428.

Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Indicator of Compromise Scanner for CVE-2019-19781

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs


Hashes for vulnerable LOG4J versions

Malware/IOC ingestion and processing engine

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…


Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…