
DFIR-LABS
Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Presented at Recon Montreal 2018

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Bash tool used for proactive detection of malicious activity on macOS systems.

An advanced memory forensics framework