
threat-research
IoCs and YARA rules from Threatray's Threat Research

IoCs and YARA rules from Threatray's Threat Research

IOCs and notes related to malware

Public repository of Sigma and YARA rules created by Synacktiv

KrustyLoader Analysis


Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Config extractor for AgentTesla - Discord/Telegram Variant

Honeypot for CVE-2025-53770 aka ToolShell

Repository containing the compromised certificate seen in recent CVE-2022-30190 (Follina) attacks.

This repository contains Yara rule and the method that a security investigator may want to use for CVE-2022-26134 threat hunting on their Linux…

Contains a simple yara rule to hunt for possible compromised KeePass config files

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y…

Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar

Collection of YARA signatures from individual research