
awesome-lists
Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

Yet another Ransomware gang tracker

Elastic Security detection content for Endpoint

Curated YARA rules and detection programs for identifying ransomware families, providing signature-based indicators for malware triage, threat…

A resource containing all the tools each ransomware gangs uses

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

A next-generation multi-echelon anti-ransomware fortress for Windows, combining hypervisor, eBPF, AI deception, and hardware-enforced security.

Apache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon…

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

the transparent ransomware claim tracker 🥷🏼🧅🖥️

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

Map tracking ransomware, by OCD World Watch team

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…