
WhacAMole
Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

CVE-2026-52813 (Gogs Path Traversal → Git Hooks RCE) defensive writeup: root-cause & patch analysis, Sigma/SIEM detection rules, IOCs, non-intrusive…

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Extract useful information from PANOS support file for CVE-2024-3400

Run on your ManageEngine server



The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World