
ThreatHound
Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

A privacy-first app that strips AI watermarks from content you own.

Rapidly Search and Hunt through Windows Forensic Artefacts


Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

Curated collection of Windows EVTX attack samples mapped to MITRE ATT&CK techniques, designed for testing detection scripts, DFIR training, and…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Direct Memory Access (DMA) Attack Software

Data from a BRAWL Automated Adversary Emulation Exercise

reverse engineering Gemini's SynthID detection

Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

Never ever ever use pixelation as a redaction technique

ThePhish: an automated phishing email analysis tool