
FLAIR
Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Repository of attack and defensive information for Business Email Compromise investigations

Decrypt GlobalProtect configuration and cookie files.

Repository for the LinkScope Client software.

A repository hosting example goodware evtx logs containing sample software installation and basic user interaction

Full-node Bitcoin client that validates transactions and blocks on the peer-to-peer network, with integrated wallet, cryptographic security, and…

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…