
ToolShell-Honeypot
Honeypot for CVE-2025-53770 aka ToolShell

Honeypot for CVE-2025-53770 aka ToolShell

Kernel-Mode Rootkit Hunter


🐍 High-performance, multi-threaded YARA & IOC scanner

Collection of private Yara rules.

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

A tool for malicious behavior detection in IoT devices

A home for detection content developed by the delivr.to team

A host based IDS written in C# Targetted at Metasploit

Small tool to play with IOCs caused by Imageload events


Generate bulk YARA rules from YAML input

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Just a git repo for the sleepmask detection rule i found in https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike/sleep-…

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y…