
libtaxii
A Python library for handling TAXII Messages invoking TAXII Services.

A Python library for handling TAXII Messages invoking TAXII Services.

Malware/IOC ingestion and processing engine

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

KQL detection rules for Microsoft Sentinel and Defender XDR covering the bikini/exploitarium anonymous disclosure — a personal research archive of…

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Extract indicators of compromise from text, including "escaped" ones.

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.


WinDbg plugin for automated malware dynamic analysis and IOC extraction. Executes within the debugger to collect predefined indicators and writes…

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Virtual Security Operations Center

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)

Advanced Phishing Protection: Suricata rulesets open and free

This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273


Open-source collaborative note-taking platform for cybersecurity and CTI teams. IOC auto-extraction, STIX 2.1 export, real-time editing, RBAC,…

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery…