#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

RAM imaging utility.

Puppet Module to help fix and migrate a Puppet deployment (CVE-2011-3872)

Removes the ability for MSDT to run, in response to CVE-2022-30190 (Follina)

Check ADC for CVE-2019-19781

MSDT protocol disabler (CVE-2022-30190 patch tool)

Kubernetes DaemonSet that hot-patches JVMs to mitigate Log4j2 vulnerabilities (CVE-2021-44228, CVE-2021-45046) by disabling JNDI lookups, providing…

These are the source codes of the Python scripts to apply the temporary protection against the CVE-2022-30190 vulnerability (Follina)

Log4Shell mitigation (CVE-2021-44228) - search and remove JNDI class from *log4j*.jar files on the system with Powershell (Windows)

List of company advisories log4j

Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

PDQ package for detecting CVE-2022-30190 (Follina) vulnerability by scanning registry keys (ms-msdt, search-ms) across Windows endpoints, enabling…

CitrixBleed 2 NetScaler honeypot logs

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

Operational security controls with forensic guarantees