
MongoBleed-DFIR-Triage-Script-CVE-2025-14847
The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

A small script to apply Yellowkey mitigation based on CVE-2026-45585 instructions



Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

My Citrix ADC NetScaler CVE-2019-19781 Vulnerability DFIR notes.

SkypeACLKeyGen.exe analysis for hacking team

🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781

Extracts and exports certificate information from digitally signed PE files using Python and pefile, enabling forensic analysis of code-signing…



Detection, analysis, and response strategies for CVE-2024-3400 exploitation attempts targeting Palo Alto PAN-OS GlobalProtect portals. Includes IOCs,…

Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.

CVE-2024-3094

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819
