
Tourmaline
Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…

Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…

An open-source digital image forensic toolset


Labs for Practical Malware Analysis & Triage

[Linux] Two Privilege Escalation techniques abusing sudo token

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

Step-by-step SOC analyst walkthrough for investigating and remediating CVE-2024-3400 (PAN-OS command injection). Covers detection, log analysis,…

Detailed incident response walkthrough analyzing CVE-2024-49138 exploitation on Windows, covering process tree analysis, IOC identification, and…

Open source Android Forensics app and framework

YARA signature and IOC database for my scanners and tools

reverse engineering Gemini's SynthID detection

Curated study notes and interview preparation guide for security engineering roles, covering networking, web security, cryptography, malware…

Self-hosted incident response platform with ticket management, automated reaction playbooks, task tracking, and dashboards for streamlining alert…

A cross platform parser for Apple UnifiedLogs!

A low pin count sniffer for ICEStick - targeting TPM chips

Powershell module for VMWare vSphere forensics

Configuration Extractors for Malware

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…