#1Digital forensics, evidence collection, timeline analysis, and incident investigation tools.
Kitploit recommended

Bash-based scanner detecting indicators of compromise from CVE-2023-3519 exploitation on Citrix ADC appliances, supporting live and forensic image…

Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361. #nsacyber

Collection of YARA signatures from individual research

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

PDQ package for detecting CVE-2022-30190 (Follina) vulnerability by scanning registry keys (ms-msdt, search-ms) across Windows endpoints, enabling…

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

Operational security controls with forensic guarantees