
ntfsDump
Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

This is the office check script provided by cPanel for all the users who are using cPanel

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Tool for checking passwords against TrueCrypt encrypted volumes and disks, and/or decrypting the data.

Documented incident response case for CVE-2024-49138 exploitation, featuring log analysis, hash validation, C2 detection, and containment procedures…

Python program to steganography files into images using the Least Significant Bit.

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool

Records calls from a Trunked Radio System (P25 & SmartNet)

bad stuffs by bad guys

An advanced memory forensics framework

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

Current links from the OSINT Inception start-me project

A verified map of reverse engineering and malware analysis. Disassemblers, unpacking, exploit dev, fuzzing, DFIR, and the deep-cut writeups other…

Semantic search over videos using Gemini Embedding 2 or Qwen3-VL.

A list of cyber-chef recipes and curated links

SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database