
CVE-2025-53770-Scanner
ToolShell scanner - CVE-2025-53770 and detection information

ToolShell scanner - CVE-2025-53770 and detection information

Public repository of Sigma and YARA rules created by Synacktiv

Centralized IoC scanner that deploys Loki across endpoints, collects detection results, and parses logs into CSV for incident response and forensic…

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.


KrustyLoader Analysis

Fingerprint SSH clients and servers.

ESXi semi-automated ransomware attacks bitcoin wallets

IOC feed and analysis toolkit for EITest campaigns, featuring C2 data decryption, victim payload decoding, and sinkhole log processing for threat…

Some of my KQL hunting queries

This package extends the Intel package to log more fields

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Detection-first incident-response toolkit for Zimbra administrators investigating CVE-2026-73570. Searches logs for exploit indicators, examines…

Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints

Run on your ManageEngine server

Extract useful information from PANOS support file for CVE-2024-3400

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Config extractor for AgentTesla - Discord/Telegram Variant