
proctools
Small toolkit for extracting information and dumping sensitive strings from Windows processes

Small toolkit for extracting information and dumping sensitive strings from Windows processes

A portable C# utility for enumerating local and remote windows sessions

Documentation and scripts to properly enable Windows event logs.

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

Post-Exploitation EVTX Analyzer for BloodHound Mapping

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

Detailed incident response walkthrough analyzing CVE-2024-49138 exploitation on Windows, covering process tree analysis, IOC identification, and…

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Extract Windows credentials directly from VM memory snapshots and virtual disks

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)

Decrypt GlobalProtect configuration and cookie files.

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Windows link file (shortcuts) examiner