
ToolShellFinder
Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

CarbonBlack hunting queries to detect PrintNightmare (CVE-2021-1675) exploitation via file, module load, and process events, based on Sigma rules.


Curated indicators of compromise (IOCs) for CVE-2019-19781, including IP addresses and whois data from honeypot logs to aid threat detection and…

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

This repo contains IoCs which are associated with exploitation of CVE-2021-4428.

A collection of IOCs for CVE-2021-44228 also known as Log4Shell

Analyzes a dark web leak of 15,000+ Fortinet devices compromised via CVE-2022-40684, providing IOCs, impacted versions, and a Python script to…

Created to help detect IOCs for CVE-2022-21894: The BlackLotus campaign

Hunting CVE-2018-13379

Sigma rule for detecting exploitation of CVE-2022-30190 (Follina) via Windows process creation events, enabling SOC teams to identify malicious…

SIEM query collection for detecting Log4Shell (CVE-2021-44228) exploitation attempts. Provides ready-to-use detection rules for security monitoring…

External Dynamic List (EDL) of IP addresses actively exploiting CVE-2024-3400, for use in firewall and SIEM blocklists to defend against ongoing…

Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Defensive detection kit for CVE-2026-76461, a critical SQL injection in Cisco Secure Email Gateway, with Sigma and YARA rules, IOCs, and remediation…

Indicator of Compromise Scanner for CVE-2019-19781

Single-page tracker recording per-distribution patch status for CVE-2025-39682, a use-after-free in the Linux kernel kTLS receive path.