
Package-Inferno
A Public Package Scanner for The Community

A Public Package Scanner for The Community

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…


Automatically create YARA rules from malicious documents.


Orbit Tracer Security Agent for intelligent security remediation. Traces vulnerability blast radius using Orbit's knowledge graph, scores risk,…

Code canaries to quickly triage hallucinated ('slop') vulnerability reports

Community curated list of templates for the nuclei engine to find security vulnerabilities.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Using code search to help fix/mitigate log4j CVE-2021-44228

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

Bash script to detect CVE-2025-55182 (React2Shell) and credential exposure in Next.js projects. Zero dependencies.