
untitledgoosetool
Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Repository of attack and defensive information for Business Email Compromise investigations

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

PowerShell module for Office 365 and Azure log collection

Data from a BRAWL Automated Adversary Emulation Exercise

Blue Team detection lab created with Terraform and Ansible in Azure.

This is an incident response playbook we created for the Vercel April 2026 compromise

Toolkit for decoding, inspecting, and modifying UEFI firmware volumes and variable stores. Supports secure boot certificate enrollment, PE binary…

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Cryptographically verifiable web archiving. Playwright capture → SHA-256 Merkle hash → Bitcoin-anchored OpenTimestamps → permanent Arweave storage.

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

Graph platform for Detection and Response