
Fennec
Artifact collection tool for *nix systems

Artifact collection tool for *nix systems

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Indicator of Compromise Scanner for CVE-2019-19781

OpenIOC rules to facilitate hunting for indicators of compromise

Bash tool used for proactive detection of malicious activity on macOS systems.

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

A Simple Log4j Indicator of Compromise Linux Detector

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…

Detection of Manjusaka C2 framework

Some of my KQL hunting queries

** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600

Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

Cloud Templates & Patterns collection <= 1.2.2 - Sensitive Information Exposure via Log File