
MISP
Open-source threat intelligence platform for collecting, correlating, and sharing structured cybersecurity indicators, malware analysis, and attack…

Open-source threat intelligence platform for collecting, correlating, and sharing structured cybersecurity indicators, malware analysis, and attack…

YARA malware query accelerator (web frontend)

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Detects compromised Elasticsearch instances by identifying ransomware, botnet infections, and malicious indices. Includes reconnaissance, exposure…

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

Detection engineering content for CVE-2025-25257, a pre-auth SQL injection in Fortinet FortiWeb leading to RCE. Includes YARA, Sigma, KQL, and Splunk…