
PAN-OS-CVE-2024-3400-Command-Injection-Investigation
Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228

Tracks impact of WS_FTP CVE-2023-40044 with affected organizations, domains, and header method analysis. Includes a news ticker for related stories.

Curated collection of public Indicators of Compromise (IoCs) for the Log4j vulnerability (CVE-2021-44228), aggregated from multiple sources for…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Curated indicators of compromise (IOCs) for CVE-2019-19781, including IP addresses and whois data from honeypot logs to aid threat detection and…

CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.

A collection of IOCs for CVE-2021-44228 also known as Log4Shell

Curated list of attacker IP addresses targeting the Log4j vulnerability (CVE-2021-44228) for threat intelligence, incident response, and network…

This repo contains IoCs which are associated with exploitation of CVE-2021-4428.

Sigma rule for detecting exploitation of CVE-2022-30190 (Follina) via Windows process creation events, enabling SOC teams to identify malicious…

External Dynamic List (EDL) of IP addresses actively exploiting CVE-2024-3400, for use in firewall and SIEM blocklists to defend against ongoing…

Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…

Collection of YARA signatures from individual research

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819