
z9
Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Detection Script for MongoBleed Exploitation

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

Zeek package for tracking long connections to report them before they have completed.

Mapping Corelight or Zeek data to Elastic Common Schema logs

This is a repo for fetching Applocker event log by parsing the win-event log


Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

Runs custom filters on Elasticsearch and alerts on matches

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

Automated forensic script hunting for cve-2019-19781


Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.