
threat-finder
Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

Hunts out CobaltStrike beacons and logs operator command output

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…


I-SOON/Anxun leak related stuff



Malicious package & supply-chain intelligence

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228

YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…

PoC for Exploiting CVE-2024-31848/49/50/51 - File Path Traversal

Technical analysis of the cPanel/WHM auth bypass



A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.