
avml
Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

This repository contains a list of new remediation scripts.

Recognizing the most likely APT groups responsible for an incident

[Linux] Two Privilege Escalation techniques abusing sudo token

Cortex: a Powerful Observable Analysis and Active Response Engine

android location service cache dumper

Python script that will extract all saved passwords from your google chrome database on windows only

Parsing Ramnit's traffic

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Kirjuri is a web application for managing cases and physical forensic evidence items.

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.