
Checkmarx-CVE-2025-30066-Detection-Tool
Scans GitHub workflows and logs for indicators of CVE-2025-30066, detecting malicious actions and exposed secrets using Checkmarx 2ms integration.

Scans GitHub workflows and logs for indicators of CVE-2025-30066, detecting malicious actions and exposed secrets using Checkmarx 2ms integration.

A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…

Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.

Indicator of Compromise Scanner for CVE-2019-19781

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

Dshell is a network forensic analysis framework.

Detect Tactics, Techniques & Combat Threats

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Incident Response collection and processing scripts with automated reporting scripts

Detection Script for MongoBleed Exploitation

A host-based IDS and network monitoring system (My graduation project)

Runs custom filters on Elasticsearch and alerts on matches

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

Extract useful information from PANOS support file for CVE-2024-3400

End-to-end SOC incident analysis and threat hunting playbook targeting Microsoft SharePoint privilege escalation (CVE-2023-29375) using SIEM logs,…

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…