
TryHack3M-Bricks-Heist
TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification

TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

My Citrix ADC NetScaler CVE-2019-19781 Vulnerability DFIR notes.

SkypeACLKeyGen.exe analysis for hacking team


Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

ESF modular ingestion tool for development and research.

Kirjuri is a web application for managing cases and physical forensic evidence items.

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…


Automates Linux swap analysis to extract user credentials, web form data, WiFi keys, and HTTP authentication during post-exploitation or forensic…

Scan files or process memory for CobaltStrike beacons and parse their configuration

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs