
LockBit-Ransomware-Analysis
Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Direct Memory Access (DMA) Attack Software

Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

Regipy is an os independent python library for parsing offline registry hives

Recognizing the most likely APT groups responsible for an incident

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

Never ever ever use pixelation as a redaction technique

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

Detailed incident report analyzing CVE-2024-24919 arbitrary file read exploit on Check Point Security Gateway, including technical analysis, response…

Cross-platform hashing toolset for computing message digests (MD5, SHA-1, SHA-256, Tiger, Whirlpool) with recursive directory traversal and file…

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.



Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)