
FLAIR
Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Collects comprehensive triage data from macOS for incident response, including system logs, file listings, browser data, shell history, and…

This is the office check script provided by cPanel for all the users who are using cPanel

CVE-2026-31431 Copy Fail Linux kernel vulnerability detection script

Detection content for CVE-2026-22557 — UniFi Network Application unauthenticated path traversal (CVSS 10.0). Includes YARA, Sigma, KQL, Splunk SPL,…

CVE-2026-41940 cPanel/WHM auth bypass IOC scanner — fixes false positives in upstream detection script, adds log cross-correlation

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database

A script that helps you understand why your E-Mail ended up in Spam

A post-processing script for TinyTracer

A Simple Log4j Indicator of Compromise Linux Detector

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Add POST body excerpt to Bro's HTTP log

Corelight@Home script

Top DNS Measurement for Bro

Zeek script and Python utility to enrich network security monitoring logs with CVE identifiers for improved threat intelligence and vulnerability…

Mapping Corelight or Zeek data to Elastic Common Schema logs

Mapping Corelight or Zeek data to Elastic Common Schema fields

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR