
LetsDefend-CVE-2022-41082-Exploitation-Attempt
Detailed incident report and educational analysis of CVE-2022-41082 (ProxyNotShell) exploitation attempt on Microsoft Exchange Server, including…

Detailed incident report and educational analysis of CVE-2022-41082 (ProxyNotShell) exploitation attempt on Microsoft Exchange Server, including…

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…

KQL detection rules for Microsoft Sentinel and Defender XDR covering the bikini/exploitarium anonymous disclosure — a personal research archive of…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Comprehensive analysis of CVE-2022-30190 (Follina MSDT vulnerability) with IOCs, detection rules for SIEMs/EDR, YARA signatures, mitigation scripts,…

This Repository Talks about the Follina MSDT from Defender Perspective

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Honeypot for CVE-2025-53770 aka ToolShell

Microsoft Threat Intelligence Security Tools