
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…


Sanitised Windows security lab demonstrating Active Directory administration, host and network detection, and layered mitigation of CVE-2021-34527.

This repository contains a list of new remediation scripts.

Forensics artefact collection tool for systems running Microsoft Windows

Powershell module for VMWare vSphere forensics

Writeup for the DEF CON 30 badge challenge

Rapidly Search and Hunt through Windows Forensic Artefacts

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Current links from the OSINT Inception start-me project

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.