
distro
Provides supplemental files and Debian package sources for a specialized Linux distro focused on malware analysis, reverse engineering, and digital…

Provides supplemental files and Debian package sources for a specialized Linux distro focused on malware analysis, reverse engineering, and digital…

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Scanner for the keyv/cacheable supply-chain attack: detects compromised npm packages, verifies payload hashes, and finds persistence implants in repo…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

Remove visible and invisible AI watermarks and provenance metadata from images and video. Python library and CLI for SynthID, C2PA, EXIF, IPTC, XMP,…

Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

This repository is to demonstrate and practice my forensic/vulnerability analysis skills by reproducing a web-related CVE in a safe environment.

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

OS X Auditor is a free Mac OS X computer forensics tool

Automated, Collection, and Enrichment Platform

Automate the creation of a lab environment complete with security tooling and logging best practices

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Labtainers: A Docker-based cyber lab framework