
TuxResponse
Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

A python script for digital image steganography using Fast Fourier Transform.

Python script that will extract all saved passwords from your google chrome database on windows only

ThePhish: an automated phishing email analysis tool

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Useful for digital forensics investigations or initial black-box pentest footprinting.

Detection and sanitization for Acropalypse Now - CVE-2023-21036

Decodes PlugX traffic and encrypted/compressed artifacts

Incident Response collection and processing scripts with automated reporting scripts

Python script for carving Bitlocker VMK keys

Linux Persistence Detection, Hunting and Artifact Collection script


A python script which allows you to parse GeoLocation data from your Image files stored in a dataset.It also produces output in CSV file and also in…

A python script developed to process Windows memory images based on triage type.

Extract AutoIt scripts embedded in PE binaries

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.