
netwatch
Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536,…

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…

Detection content for CVE-2026-22557 — UniFi Network Application unauthenticated path traversal (CVSS 10.0). Includes YARA, Sigma, KQL, Splunk SPL,…

Detection rules and YARA/KQL signatures for CVE-2025-60787, an unauthenticated RCE in motionEye via config injection, with process execution and file…

Config extractor for AgentTesla - Discord/Telegram Variant

Config Extractor for Asyncrat/Dcrat/VenomRat

Scans a list of raccoon servers from Tria.ge and extracts the config

Python config extractors for malware families including PlugX, Remcos, templateX, and RedLine Stealer, supporting C2 configuration extraction for…

Contains a simple yara rule to hunt for possible compromised KeePass config files

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.