
MemProcFS-Analyzer
Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Static vulnerability findings tracker with parallel search across 11 CVE databases, EPSS enrichment, CISA KEV badges, coordinated disclosure…

Collection of YARA signatures from individual research

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Indicator of Compromise Scanner for CVE-2019-19781

List of company advisories log4j

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

LDAP Watchdog: A real-time linux-compatible LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications,…

Tracking history of USB events on GNU/Linux

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support


Detect Tactics, Techniques & Combat Threats

ThePhish: an automated phishing email analysis tool

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders


Regipy is an os independent python library for parsing offline registry hives