
ad-honeypot-autodeploy
Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.

Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

Low-interaction honeypot that emulates vulnerable network services to capture malware, shellcode, and exploit attempts, with IPv6 and TLS support.

Hashes for vulnerable LOG4J versions

Scan your Windows computer for known vulnerable or malicious drivers.

An open-source, single-script CVE scanner for RMM-managed fleets. Pure PowerShell 7 — joins your RMM software inventory against NVD, CISA KEV, EPSS…

HASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).

Zeek package detecting CVE-2022-3602 exploitation attempts and vulnerable OpenSSL servers via HTTP Server header and TLS punycode anomalies,…

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…

Zeek script to detect servers vulnerable to CVE-2020-13777

L1 SOC Analysis: OSINT detection and risk validation of publicly exposed MikroTik RouterOS vulnerable to RCE | Tools: Shodan, NIST NVD

A vulnerable Boa web server detector.

A critical pre-authentication Remote Code Execution (RCE) flaw in Oracle E-Business Suite (versions 12.2.3 - 12.2.14) allows attackers to gain full…

A Rust honeypot that simulates a vulnerable cPanel/WHM instance for CVE-2026-41940

Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.


Educational analysis of the Log4Shell (CVE-2021-44228) vulnerability, detailing its exploitation in a cryptocurrency mining campaign with IoCs, MITRE…

Enhance your malware detection with WAF + YARA (WAFARAY)