
jarm
Active TLS server fingerprinting tool that sends crafted Client Hello packets to generate unique JARM hashes for identifying server configurations,…

Active TLS server fingerprinting tool that sends crafted Client Hello packets to generate unique JARM hashes for identifying server configurations,…

This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

Daily collection of malicious samples originating from Vietnam for malware analysis, threat intelligence, and detection engineering research.

A utility to safely generate malicious network traffic patterns and evaluate controls.

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…

Detects malicious IPv4 addresses and domain names associated with a web application by comparing against local threat intelligence lists of known…

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Proof-of-concept and technical analysis of CVE-2025-0411, a 7-Zip Mark-of-the-Web bypass vulnerability exploited in SmokeLoader campaigns, with…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered…

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Curated repository of detection information and validation guidance for identifying malicious activity in enterprise environments.

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

SOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege…