
MISP
MISP (core software) - Open Source Threat Intelligence and Sharing Platform

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT

Forensic triage toolkit for Citrix NetScaler devices, featuring a Dissect-based IOC scanner for webshells, timestomping, and suspicious binaries,…

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such…

Zeek script and Python utility to enrich network security monitoring logs with CVE identifiers for improved threat intelligence and vulnerability…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…


Fingerprint SSH clients and servers.

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Scanner de IOCs del ataque de cadena de suministro TeamPCP (CVE-2026-33634).

A simple bash script to check for evidence of compromise related to CVE-2024-3400

my advisory, poc, slides and scripts related to IoT/protocol security

Bash-based scanner detecting indicators of compromise from CVE-2023-3519 exploitation on Citrix ADC appliances, supporting live and forensic image…

Honeypot for CVE-2025-53770 aka ToolShell

Signatures and IoCs from public Volexity blog posts.

Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.