
chainsaw
Rapidly Search and Hunt through Windows Forensic Artefacts

Rapidly Search and Hunt through Windows Forensic Artefacts

Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)

Curated collection of Windows EVTX attack samples mapped to MITRE ATT&CK techniques, designed for testing detection scripts, DFIR training, and…

A privacy-first app that strips AI watermarks from content you own.

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Scanner for the keyv/cacheable supply-chain attack: detects compromised npm packages, verifies payload hashes, and finds persistence implants in repo…

Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups

Recognizing the most likely APT groups responsible for an incident

Repository of attack and defensive information for Business Email Compromise investigations

Never ever ever use pixelation as a redaction technique


Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack

Detailed incident report analyzing CVE-2024-24919 arbitrary file read exploit on Check Point Security Gateway, including technical analysis, response…

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).