
cpanel-cve-2026-41940-ioc
CVE-2026-41940 cPanel/WHM auth bypass IOC scanner — fixes false positives in upstream detection script, adds log cross-correlation

CVE-2026-41940 cPanel/WHM auth bypass IOC scanner — fixes false positives in upstream detection script, adds log cross-correlation

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Detection Script for MongoBleed Exploitation

AWS Organization-wide detection toolkit for CVE-2025-55182 & CVE-2025-66478 (React Server Components / Next.js RCE vulnerabilities)

A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…

A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282,…

Zeek script and Python utility to enrich network security monitoring logs with CVE identifiers for improved threat intelligence and vulnerability…

Incident Response collection and processing scripts with automated reporting scripts

Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.

Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.

A post-processing script for TinyTracer

This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Local F5 BIG-IP script that scans for Indicators of Compromise (IoCs) related to CVE-2020-5902, checking logs, files, and system integrity to detect…