
ToolShell-Honeypot
Honeypot for CVE-2025-53770 aka ToolShell

Honeypot for CVE-2025-53770 aka ToolShell

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

This repository contains Yara rule and the method that a security investigator may want to use for CVE-2022-26134 threat hunting on their Linux…

Contains a simple yara rule to hunt for possible compromised KeePass config files

Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

Threat-Informed Detection & Mitigation Package for MOVEit Transfer Vulnerability



IOCs for CVE-2019-19781

CVE-2022-28672 Vulnerabilidad Foxit PDF Reader - UaF - RCE - JIT Spraying

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.

La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y…

Data we are receiving from our honeypots about CVE-2021-44228

Created to help detect IOCs for CVE-2022-21894: The BlackLotus campaign



KQL para deteccion de CVE-2025-21333 en Sentinel