
cve-2026-22557-unifi-detection
Detection content for CVE-2026-22557 — UniFi Network Application unauthenticated path traversal (CVSS 10.0). Includes YARA, Sigma, KQL, Splunk SPL,…

Detection content for CVE-2026-22557 — UniFi Network Application unauthenticated path traversal (CVSS 10.0). Includes YARA, Sigma, KQL, Splunk SPL,…

Python config extractors for malware families including PlugX, Remcos, templateX, and RedLine Stealer, supporting C2 configuration extraction for…

Scans a list of raccoon servers from Tria.ge and extracts the config

Config Extractor for Asyncrat/Dcrat/VenomRat

Config extractor for AgentTesla - Discord/Telegram Variant

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Contains a simple yara rule to hunt for possible compromised KeePass config files

Detection rules and YARA/KQL signatures for CVE-2025-60787, an unauthenticated RCE in motionEye via config injection, with process execution and file…

Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)

Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536,…

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.