
associated-threat-analyzer
Detects malicious IPv4 addresses and domain names associated with a web application by comparing against local threat intelligence lists of known…

Detects malicious IPv4 addresses and domain names associated with a web application by comparing against local threat intelligence lists of known…

Web application for aggregating and analyzing cyber threat intelligence from multiple feeds and APIs, enabling cross-search of indicators, automated…

A centralized and enhanced memory analysis platform

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Defensive mitigation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel plugin, providing symlink detection, IOC hunting, and remediation…

Defensive remediation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel Plugin. Automates patching, detects suspicious symlinks, hunts…

Asynchronous forensic data ingestion and analysis framework with Elasticsearch backend, supporting Mandiant Redline and FireEye HX audits, timeline…

TAXII server implementation in Python from EclecticIQ

Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

SSH-based utility to check FortiGate firewalls for indicators of compromise (IoCs) associated with CVE-2022-42475, running commands from Fortinet's…