
gundog
gundog - guided hunting in Microsoft Defender

gundog - guided hunting in Microsoft Defender

ToolShell scanner - CVE-2025-53770 and detection information

Post-Exploitation EVTX Analyzer for BloodHound Mapping

Basic log analysis tool to detect impossible travel via IP address geographic information

Spip network sensor written in Go

Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

Wazuh detection rules for CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite, monitoring web access logs and zimbra.log for…

a terminal UI to browse bbot reports

This package extends the Intel package to log more fields

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

KQL Hunting for WinRAR CVE-2023-38831

Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints

Run on your ManageEngine server

Detection signatures for CVE-2026-41940 and shemas for cPanel logs

Threat hunting query for bluehammer CVE windows CVE-2026-33825

Sigma rule for detecting scanning activity targeting CVE-2021-22005, enabling threat detection and log-based intrusion analysis.

Cloud Templates & Patterns collection <= 1.2.2 - Sensitive Information Exposure via Log File
