
Windows-Defender-Security-Auditor-CVE-2026-50656-
Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Defensive remediation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel Plugin. Automates patching, detects suspicious symlinks, hunts…

Defensive mitigation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel plugin, providing symlink detection, IOC hunting, and remediation…

test for the ioc described for FG-IR-22-398

EXIST is a web application for aggregating and analyzing cyber threat intelligence.

A centralized and enhanced memory analysis platform

Detects malicious IPv4 addresses and domain names associated with a web application by comparing against local threat intelligence lists of known…

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

TAXII server implementation in Python from EclecticIQ

Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Incident Response Forensic Framework