
CVE-2024-3400-Compromise-Checker
A simple bash script to check for evidence of compromise related to CVE-2024-3400

A simple bash script to check for evidence of compromise related to CVE-2024-3400

CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

A powerful and flexible tool to apply active attacks for disrupting stegomalware

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

Zeek package for tracking long connections to report them before they have completed.

Mapping Corelight or Zeek data to Elastic Common Schema logs

A Zeek package to detect CVE-2021-42292, a Microsoft Excel local privilege escalation exploit.

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

Selective protocol extractor from PCAPs or interfaces

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.