
Mortimer
A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

A collection of IOCs for CVE-2021-44228 also known as Log4Shell

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Curated collection of public Indicators of Compromise (IoCs) for the Log4j vulnerability (CVE-2021-44228), aggregated from multiple sources for…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Curated vulnerability writeups with full technical analysis, proof-of-concept scripts, IOC listings, and remediation guidance for real-world software…

Curated vulnerability research repository with in-depth writeups, PoC scripts, and IOC detection tools for real-world security incidents like…

Curated collection of indicators of compromise extracted from real-world malware investigations, including hashes, domains, and IPs for threat…

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

A centralized and enhanced memory analysis platform

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Curated dataset of IPs, ASNs, and SMTP banners for Exim CVE-2019-10149, with linked advisories and threat actor intelligence for vulnerability…

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

Curated collection of detection rules and IOCs extracted from DFIR engagements and malware analyses to support threat hunting, incident response, and…

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

SIEM query collection for detecting Log4Shell (CVE-2021-44228) exploitation attempts. Provides ready-to-use detection rules for security monitoring…

Collection of YARA signatures from individual research

Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…