
Detections-CVE-2026-23918
Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

Advanced Phishing Protection: Suricata rulesets open and free

Curated repository of Indicators of Compromise (IOCs), attack source IPs, and Snort/Suricata detection rules for Log4Shell (CVE-2021-44228) attacks.

Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…


SIEM query collection for detecting Log4Shell (CVE-2021-44228) exploitation attempts. Provides ready-to-use detection rules for security monitoring…

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

cve-2025-8088_detection

Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.

Signatures and IoCs from public Volexity blog posts.

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

🐍 High-performance, multi-threaded YARA & IOC scanner

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.

Public repository of Sigma and YARA rules created by Synacktiv

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Fingerprint SSH clients and servers.

Detects shadow-administrator accounts in WordPress via configurable indicators and heuristics, then removes selected accounts through guarded, logged…