
PayloadAutomation
Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…

Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…

Static analysis of malicious Python code

TAXII server implementation in Python from EclecticIQ

CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

A Python library for handling TAXII Messages invoking TAXII Services.

A Python-based security scanner for identifying the CVE-2025-31324 vulnerability in SAP Visual Composer systems, and detecting known Indicators of…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Analyzes a dark web leak of 15,000+ Fortinet devices compromised via CVE-2022-40684, providing IOCs, impacted versions, and a Python script to…

Python script to check Palo Alto firewalls for CVE-2024-3400 exploit attempts

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Open Vulnerability Intelligence platform, aggregated intel in one dashboard, with correlation and IOC lookups, completely self hosted. All resources…

A curated list of awesome YARA rules, tools, and people.

Cortex: a Powerful Observable Analysis and Active Response Engine


Extract indicators of compromise from text, including "escaped" ones.

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…