
moneta
Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

Hardware Sandbox Toolkit

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Static analysis of malicious Python code

A Simple Log4j Indicator of Compromise Linux Detector

Defense Against the Shai-Hulud Supply Chain Attack


Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Created to help detect IOCs for CVE-2022-21894: The BlackLotus campaign

Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during…

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows