
OpenTAXII
TAXII server implementation in Python from EclecticIQ

TAXII server implementation in Python from EclecticIQ

Static analysis of malicious Python code

Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during…

Python script to check Palo Alto firewalls for CVE-2024-3400 exploit attempts

Python Decoders for Common Remote Access Trojans

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

A Python library for handling TAXII Messages invoking TAXII Services.

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Aggregate, filter, and track CVEs from multiple sources with team collaboration, custom dashboards, alerts, and AI-powered analysis for vulnerability…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

ThePhish: an automated phishing email analysis tool

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.