
CVE-2026-76461-Detection-Kit-
Defensive detection kit for CVE-2026-76461, a critical SQL injection in Cisco Secure Email Gateway, with Sigma and YARA rules, IOCs, and remediation…

Defensive detection kit for CVE-2026-76461, a critical SQL injection in Cisco Secure Email Gateway, with Sigma and YARA rules, IOCs, and remediation…

Detection-first incident-response toolkit for Zimbra administrators investigating CVE-2026-73570. Searches logs for exploit indicators, examines…

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.


A Simple Log4j Indicator of Compromise Linux Detector

Zeek script and Python utility to enrich network security monitoring logs with CVE identifiers for improved threat intelligence and vulnerability…

This package extends the Intel package to log more fields

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Extract useful information from PANOS support file for CVE-2024-3400

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

CarbonBlack hunting queries to detect PrintNightmare (CVE-2021-1675) exploitation via file, module load, and process events, based on Sigma rules.

Automated forensic script hunting for cve-2019-19781