



DPS' Lightweight Investigation Notebook

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Indicators of Compromise from Amnesty International's cyber investigations

Scan files or process memory for CobaltStrike beacons and parse their configuration

Defanged Indicator of Compromise (IOC) Extractor.

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Extract indicators of compromise from text, including "escaped" ones.

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Public repository of Sigma and YARA rules created by Synacktiv

Fingerprint SSH clients and servers.

Forensic intelligence platform that analyzes files, correlates threat indicators, maps behavior to MITRE ATT&CK, and generates actionable security…

Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar


Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs