
Microsoft-Extractor-Suite
A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.


Automate the creation of a lab environment complete with security tooling and logging best practices

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Collection of some easy of use tools - in powershell.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865