
DFIR4vSphere
Powershell module for VMWare vSphere forensics

Powershell module for VMWare vSphere forensics

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

Incident Response collection and processing scripts with automated reporting scripts

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.