


Contains a simple yara rule to hunt for possible compromised KeePass config files

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related…

A Simple Log4j Indicator of Compromise Linux Detector

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

A simple bash script to check for evidence of compromise related to CVE-2024-3400

test for the ioc described for FG-IR-22-398

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

🐍 High-performance, multi-threaded YARA & IOC scanner

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Forensic triage toolkit for Citrix NetScaler devices, featuring a Dissect-based IOC scanner for webshells, timestomping, and suspicious binaries,…

Indicator of Compromise Scanner for CVE-2019-19781

Black-box vulnerability scanner and indicator-of-compromise analyzer for CVE-2020-6287 (RECON) in SAP NetWeaver Java applications, enabling rapid…

This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273