
THM-Tempest
TryHackMe SOC Level 1 — Follina CVE-2022-30190, Nim C2, Chisel, PrintSpoofer, backdoor accounts

TryHackMe SOC Level 1 — Follina CVE-2022-30190, Nim C2, Chisel, PrintSpoofer, backdoor accounts

End-to-end SOC incident analysis and threat hunting playbook targeting Microsoft SharePoint privilege escalation (CVE-2023-29375) using SIEM logs,…

A forensic evidence collection & analysis toolkit for OS X

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

Writeup for the DEF CON 30 badge challenge


🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

PoC, IOCs, and detection logic for the SharePoint /_trust WS-Federation BinaryFormatter deserialization chain. Lab reconstruction covering…

🔵 Threat analysis writeup for Follina (CVE-2022-30190) — Microsoft MSDT RCE zero-day exploited in the wild. Covers static analysis, VirusTotal,…

Forensic Analysis for Mobile Apps (FAMA) -- module for the Autopsy Forensic Browser

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

Read, understand and silence the Windows GDID device identifier (the ID that tracked a hacker through a VPN). Verified on a real Win11 VM. Honest: it…

Tools for the Computer Incident Response Team :computer:

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

This script checks the Citrix Netscaler if it has been compromised by CVE-2019-19781 attacks and collects all file system information

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…