


ToolShell scanner - CVE-2025-53770 and detection information

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Centralized IoC scanner that deploys Loki across endpoints, collects detection results, and parses logs into CSV for incident response and forensic…

Spip network sensor written in Go

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain


A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Public IoCs about log4j CVE-2021-44228

Detects shadow-administrator accounts in WordPress via configurable indicators and heuristics, then removes selected accounts through guarded, logged…

Reproducible SOC lab for CVE-2024-4577 detection and response

IoC determination for exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.

Vulnerability CVE-2021-44228 allows remote code execution without authentication for several versions of Apache Log4j2 (Log4Shell). Attackers can…

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…

CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…