
CitrixNetscalerAnalysis
🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781

🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781


FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

TIH is an intelligence tool that helps you in searching for IOCs across multiple openly available security feeds and some well known APIs. The idea…

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

OpenIOC rules to facilitate hunting for indicators of compromise

A centralized and enhanced memory analysis platform

A tool for simplifying the process of researching IOCs.

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Defense Against the Shai-Hulud Supply Chain Attack

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771