
Zeek-CVE-Enrichment
Zeek script and Python utility to enrich network security monitoring logs with CVE identifiers for improved threat intelligence and vulnerability…

Zeek script and Python utility to enrich network security monitoring logs with CVE identifiers for improved threat intelligence and vulnerability…

Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Python script to check Palo Alto firewalls for CVE-2024-3400 exploit attempts

HexaLocker ransomware analysis

PoC & IOCs for critical HSM authentication bypass (CVE-2025-99999). Threat intelligence for financial sector.

IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

Scanner de IOCs del ataque de cadena de suministro TeamPCP (CVE-2026-33634).

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and…

This repository contains Yara rule and the method that a security investigator may want to use for CVE-2022-26134 threat hunting on their Linux…

Repository containing the compromised certificate seen in recent CVE-2022-30190 (Follina) attacks.


Contains a simple yara rule to hunt for possible compromised KeePass config files

cve-2025-8088_detection

Sigma-Rule-for-CVE-2021-40438-Attack-Attemp

Honeypot for CVE-2025-53770 aka ToolShell