
ZeroPoint
This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

This repo contains IoCs which are associated with exploitation of CVE-2021-4428.

Indicator of Compromise Scanner for CVE-2019-19781

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Tracking history of USB events on GNU/Linux

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Dshell is a network forensic analysis framework.

Detect Tactics, Techniques & Combat Threats

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

Apache Real Time Logs Analyzer System

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…