
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Threat hunting command system for agentic IDEs

Local F5 BIG-IP script that scans for Indicators of Compromise (IoCs) related to CVE-2020-5902, checking logs, files, and system integrity to detect…

Forensic analysis of a TeamCity server compromise via CVE-2024-27198, detailing initial access, webshell persistence, and system enumeration from…

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…

Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and…

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes vulnerability analysis, detection rules…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Python-based scanner for CVE-2025-31324 that identifies vulnerable SAP NetWeaver Visual Composer instances and detects indicators of compromise from…

SAP NetWeaver vulnerability and compromise assessment tool that detects CVE-2025-31324/42999, scans for IOCs, analyzes HTTP access and Java trace…

Automated shell script to detect traces of CVE-2019-19781 exploitation on Citrix ADC/Gateway systems by scanning logs and files for indicators of…

Deploy a TPOT honeypot for threat intelligence collection, real-time attack monitoring, and malicious IP aggregation with Elastic/Kibana log analysis.

Curated JSON object templates that define MISP attributes and relationship types for structured threat intelligence sharing and interoperable IOC…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…