
ioccheck
A tool for simplifying the process of researching IOCs.

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

A low to medium interaction honeypot.

AI 驱动的 SOC 仿真平台

Intelligent threat hunter and phishing servers

A repository to release detection rules to the public

CVE-2026-54984 / ZDI-26-543: Windows ICC file parsing out-of-bounds write (CWE-122, CVSS 7.8)

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…

Anteater - CI/CD Gate Check Framework

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Community curated list of templates for the nuclei engine to find security vulnerabilities.

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

Graph-based threat detection system using inexact graph vector matching to compare threat graphs with CTI-derived attack query graphs for automated…

YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…

Collects macOS and iOS artifacts to build timelines of network activity, cross-device identity, and physical location correlation for reconnaissance…