
zeek-gozi-detector
A Zeek based Gozi banking malware detector.

A Zeek based Gozi banking malware detector.

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring,…

Hunts for potential malware downloads and suspicious domain calls via common Windows LOLBins using YARA rules and Nexthink telemetry modules.

Signatures and IoCs from public Volexity blog posts.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

ETW based POC to identify direct and indirect syscalls


The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…

Public repository of Sigma and YARA rules created by Synacktiv

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

Detection reverse shell and kill it before trying shell.

Elastic Security detection content for Endpoint

A smart gateway to stop cyber criminals - Sponsored by Falcon Guard

A Zeek based AsyncRAT malware detector.