
dfir-orc
Forensics artefact collection tool for systems running Microsoft Windows

Forensics artefact collection tool for systems running Microsoft Windows

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

Android client for Prey: reliable device tracking and security tool

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

0-day malware detection for binaries, source & scripts (that doesn't suck)

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Web Shell Detector – is a php script that helps you find and identify php/cgi(perl)/asp/aspx shells. Web Shell Detector has a “web shells” signature…

Find your device and control it remotely. Works over SMS, instant messengers, or FMD Server's web interface. A secure open source alternative to…

Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Slack enumeration and exposed secrets detection tool

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

CommunityHoneyNetwork Server