
LetsDefend--SOC-342-CVE-2025-53770-SharePoint-Exploit-ToolShell
Detailed walkthrough of CVE-2025-53770 (ToolShell) SharePoint zero-day exploitation, including RCE analysis, MachineKey exfiltration, payload…

Detailed walkthrough of CVE-2025-53770 (ToolShell) SharePoint zero-day exploitation, including RCE analysis, MachineKey exfiltration, payload…

Educational demonstration of CVE-2023-32784 KeePass master password recovery via memory dump analysis, with step-by-step exploit setup and mitigation…

Step-by-step walkthrough of exploiting CVE-2025-53770 (ToolShell) in a LetsDefend lab, covering RCE, web shell deployment, and incident response…

Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.

Curated collection of Windows EVTX attack samples mapped to MITRE ATT&CK techniques, designed for testing detection scripts, DFIR training, and…

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

SOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege…

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Distributed & real time digital forensics at the speed of the cloud

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

CLI tools for forensic investigation of Windows artifacts

Differential Analysis of Malware in Memory

Tracking history of USB events on GNU/Linux

Semantic search over videos using Gemini Embedding 2 or Qwen3-VL.

A free, open-source, and cross-platform iDevice management tool

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders