
Malcolm
Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Indicator of Compromise Scanner for CVE-2019-19781

OpenIOC rules to facilitate hunting for indicators of compromise

Local F5 BIG-IP script that scans for Indicators of Compromise (IoCs) related to CVE-2020-5902, checking logs, files, and system integrity to detect…

ToolShell scanner - CVE-2025-53770 and detection information

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

A Simple Log4j Indicator of Compromise Linux Detector

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

Some of my KQL hunting queries

This package extends the Intel package to log more fields

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Detection-first incident-response toolkit for Zimbra administrators investigating CVE-2026-73570. Searches logs for exploit indicators, examines…