
CVE-2022-29072
** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…

** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

Runs custom filters on Elasticsearch and alerts on matches

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600

Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

This repo contains IoCs which are associated with exploitation of CVE-2021-4428.

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Indicator of Compromise Scanner for CVE-2019-19781

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

LDAP Watchdog: A real-time linux-compatible LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications,…