
phantomprint
Passive hybrid fingerprinting engine — identify hosts without sending a single packet

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

Powershell module for VMWare vSphere forensics

Incident Response collection and processing scripts with automated reporting scripts

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781