
CVE-2019-19781-DFIR-Notes
My Citrix ADC NetScaler CVE-2019-19781 Vulnerability DFIR notes.

My Citrix ADC NetScaler CVE-2019-19781 Vulnerability DFIR notes.

Kirjuri is a web application for managing cases and physical forensic evidence items.

Library and tools to access the Windows New Technology File System (NTFS)

Library and tools to access the VMware Virtual Disk (VMDK) format

Library and tools to access the Virtual Hard Disk (VHD) image format

Library and tools to access the Volume Shadow Snapshot (VSS) format

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Library to access the Windows Shell Item format

A canary designed to minimize the impact from certain Ransomware actors

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

Technical analysis of a SharePoint ToolShell (CVE-2025-53770) exploitation attempt involving RCE, webshell deployment, and MachineKey extraction.


C library and command-line toolkit for forensic EWF image handling: acquire, export, verify, recover, and mount evidence files in EnCase and SMART…

Binary and Directory tree comparison tool using Fuzzy Hashing

Framework for hashing declared permissions in Chromium extensions and APKs, enabling clustering, hunting, and pivoting across potentially malicious…

TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification