
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Credential and sensitive-data exposure triage for file shares

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

A community‑driven cybersecurity knowledge base with 400+ notes, mind‑maps, and cheat‑sheets – built from first principles. Ideal for students, SOC…



This repository contains a list of new remediation scripts.

Forensics artefact collection tool for systems running Microsoft Windows

Collection of some easy of use tools - in powershell.

Powershell module for VMWare vSphere forensics

Writeup for the DEF CON 30 badge challenge

Current links from the OSINT Inception start-me project

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

Documentation and scripts to properly enable Windows event logs.