
threat-intel
Signatures and IoCs from public Volexity blog posts.

Signatures and IoCs from public Volexity blog posts.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.

Public repository of Sigma and YARA rules created by Synacktiv

Detects shadow-administrator accounts in WordPress via configurable indicators and heuristics, then removes selected accounts through guarded, logged…

Fingerprint SSH clients and servers.

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.


HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

Honeypot for CVE-2025-53770 aka ToolShell

cve-2025-8088_detection

🐍 High-performance, multi-threaded YARA & IOC scanner


USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Sigma-Rule-for-CVE-2021-40438-Attack-Attemp

A simple bash script to check for evidence of compromise related to CVE-2024-3400