
RansomCoinPublic
A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Defense Against the Shai-Hulud Supply Chain Attack

TIH is an intelligence tool that helps you in searching for IOCs across multiple openly available security feeds and some well known APIs. The idea…

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

Static analysis of malicious Python code

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441


IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

A tool for studying JavaScript malware.

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

