
synacktiv-rules
Public repository of Sigma and YARA rules created by Synacktiv

Public repository of Sigma and YARA rules created by Synacktiv


KrustyLoader Analysis

IoC determination for exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.

ESXi semi-automated ransomware attacks bitcoin wallets

Some of my KQL hunting queries

This package extends the Intel package to log more fields


Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

PoC & IOCs for critical HSM authentication bypass (CVE-2025-99999). Threat intelligence for financial sector.

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

Automated forensic script hunting for cve-2019-19781

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Extract useful information from PANOS support file for CVE-2024-3400

Run on your ManageEngine server

IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…