
Unit42-Threat-Intelligence-Article-Information
This is the repository for indicators of compromise (IOCs) and other data for threat intelligence articles posted on the Palo Alto Networks Unit 42…

This is the repository for indicators of compromise (IOCs) and other data for threat intelligence articles posted on the Palo Alto Networks Unit 42…

Curated public database of indicators of compromise aggregated by Wiz Research for threat detection, hunting, and incident response workflows.

A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).

Curated repository of threat actor aliases and naming schemes used by major threat intelligence vendors, enabling cross-vendor search, attribution,…

Open platform for modelling, collection and exchange of knowledge

A comprehensive tool that provides an insightful analysis of Microsoft's monthly security updates.

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

A repository of my own Sigma detection rules.

A web-based tool to assist the work of the intuitive threat analysts.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.

Curated repository of Indicators of Compromise (IOCs), attack source IPs, and Snort/Suricata detection rules for Log4Shell (CVE-2021-44228) attacks.

OpenIOC rules to facilitate hunting for indicators of compromise

Detects malicious IPv4 addresses and domain names associated with a web application by comparing against local threat intelligence lists of known…

Structured OSINT dataset of LockBit ransomware-linked identities, including usernames, IDs, join dates, Bitcoin addresses, and media artifacts for…