
Exploitarium-Detections
KQL detection rules for Microsoft Sentinel and Defender XDR covering the bikini/exploitarium anonymous disclosure — a personal research archive of…

KQL detection rules for Microsoft Sentinel and Defender XDR covering the bikini/exploitarium anonymous disclosure — a personal research archive of…

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Collects and organizes malware indicators of compromise (IOCs) for rapid threat detection, incident response, and actionable intelligence sharing.

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

A continuously updated resource that catalogs confirmed data breaches from across the globe. Each entry includes the breach name, usually aligned…

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

WinDbg plugin for automated malware dynamic analysis and IOC extraction. Executes within the debugger to collect predefined indicators and writes…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT

Forensic triage toolkit for Citrix NetScaler devices, featuring a Dissect-based IOC scanner for webshells, timestomping, and suspicious binaries,…

Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…

Curated repository of Indicators of Compromise (IOCs), attack source IPs, and Snort/Suricata detection rules for Log4Shell (CVE-2021-44228) attacks.

Advanced Phishing Protection: Suricata rulesets open and free

Open-source threat intelligence platform for malware and observable analysis. Enriches IPs, domains, URLs, and hashes with external sources, performs…