
CyberThreatIntel
Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups

Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups

Generate list of potential typo squatting domains with domain name permutation engine to feed AIL and other systems.

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Technical analysis of the cPanel/WHM auth bypass


Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

Competitive Intelligence from public data sources. Named after Coeus, the Greek Titan of the inquisitive mind.

A continuously updated resource that catalogs confirmed data breaches from across the globe. Each entry includes the breach name, usually aligned…

DepAlert is an open-source security gate for your CI/CD pipeline. It analyzes SBOMs against malware intelligence data and quickly tells you whether…

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Domain Enrichment Toolkit $ pip install richkit

Domain name permutation engine written in Go

Enhance your malware detection with WAF + YARA (WAFARAY)

InfoHound is an OSINT to extract a large amount of data given a web domain name.