
Zeek-Endpoint-Enrichment
Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current privilege…

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered…

Scanning pastebin with yara rules

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape

Tracking ITScape (CVE-2026-46316), the KVM/arm64 guest-to-host escape

NetSpecter is a lightweight yet powerful asynchronous OSINT and reconnaissance engine built in Python.

Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)