
drovorub-hunt
A tool to assist with network-based hunting for GRU's Drovorub malware c2

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Web interface for Suricata ruleset management, threat hunting, and rule tuning with multi-source feed aggregation, transformation, and activity…

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

Dynamically generated Suricata rules from real-time threat feeds

Signatures and IoCs from public Volexity blog posts.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

Public repository of Sigma and YARA rules created by Synacktiv

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…


DShield Sensor Log Collection with ELK

A collection of IOCs for CVE-2021-44228 also known as Log4Shell

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Advanced Phishing Protection: Suricata rulesets open and free

YARA signature and IOC database for my scanners and tools

Live Feed of C2 servers, tools, and botnets

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…