
routeros-scanner
Tool to scan for RouterOS (Mikrotik) forensic artifacts and vulnerabilities.

Tool to scan for RouterOS (Mikrotik) forensic artifacts and vulnerabilities.

Collection of DFIR and OSINT Python scripts for parsing malicious LNK samples, extracting OLE objects from MHTML, and hashing favicons to hunt…

GUI analyzer for deep-diving into PDF files. Detect malicious payloads, understand object relationships, and extract key information for threat…

Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)

Proof-of-concept script that analyzes Windows memory dumps to recover visited Tor onion services, bypassing Tor Browser's anonymity by exploiting…

Collects macOS and iOS artifacts to build timelines of network activity, cross-device identity, and physical location correlation for reconnaissance…

Telegram OSINT, scraping and archival as a local web app. Multi-account collection, profile lookup with historic photos and change diffs, ten export…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

This repository contains a list of new remediation scripts.

Forensics artefact collection tool for systems running Microsoft Windows

Current links from the OSINT Inception start-me project

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

An OSINT / digital forensics tool built in Python


A tool to use novel locations to extract metadata from Office documents.

Active Directory NTDS database parser that dumps records to JSON, supports object filtering, and decrypts encrypted columns using SYSTEM hive or…

Cortex: a Powerful Observable Analysis and Active Response Engine