
OreNPMGuard
Defense Against the Shai-Hulud Supply Chain Attack

Defense Against the Shai-Hulud Supply Chain Attack

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778): verifies build, CVE preconditions and upgrade risks, and sweeps public IoCs…

Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…

Repo containing all info, scripts, etc. related to CVE-2021-44228

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Indicator of Compromise Scanner for CVE-2019-19781

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes vulnerability analysis, detection rules…

Indicator of Compromise Scanner for CVE-2019-19781

Publishes Kiteworks security advisories and CVE disclosures, including vulnerability details, disclosure policy, and bug bounty information for…

Spip network sensor written in Go


Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

TAXII server implementation in Python from EclecticIQ

Extract indicators of compromise from text, including "escaped" ones.