

Parses Apple Unified Logs to extract process, thread, activity, timestamp, and message metadata from logarchives or live macOS systems into JSONL/CSV…

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

Recognizing the most likely APT groups responsible for an incident

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

A Windows kernel dump C++ parser library with Python 3 bindings.

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

Extract AutoIt scripts embedded in PE binaries

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

« usbkill » is an anti-forensic kill-switch that waits for a change on your USB ports and then immediately shuts down your computer.

A tool to use novel locations to extract metadata from Office documents.

[Linux] Two Privilege Escalation techniques abusing sudo token

Read, understand and silence the Windows GDID device identifier (the ID that tracked a hacker through a VPN). Verified on a real Win11 VM. Honest: it…

android location service cache dumper

Python script that will extract all saved passwords from your google chrome database on windows only

A python tool that will extract exif data from picture with two methods