
TEx
Telegram intelligence collection tool for researchers and investigators. Scrapes groups, messages, media, and user data with OCR, Elasticsearch…

Telegram intelligence collection tool for researchers and investigators. Scrapes groups, messages, media, and user data with OCR, Elasticsearch…

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Extract indicators of compromise from text, including "escaped" ones.

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Public repository of Sigma and YARA rules created by Synacktiv

Fingerprint SSH clients and servers.

Forensic intelligence platform that analyzes files, correlates threat indicators, maps behavior to MITRE ATT&CK, and generates actionable security…

Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar

Hunt down social media accounts by username across social networks

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.


Advanced SMB Honeypot: CVE-2025-33073 Research & Implementation

YARA malware query accelerator (web frontend)