
Threat-Remediation-Scripts
This repository contains a list of new remediation scripts.

This repository contains a list of new remediation scripts.

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Telegram intelligence collection tool for researchers and investigators. Scrapes groups, messages, media, and user data with OCR, Elasticsearch…

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

Visualize the virtual address space of a Windows process on a Hilbert curve.

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Artifact collection tool for *nix systems

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

macOS forensic timeline generator using the analysis result DBs of mac_apt

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

Indicator of Compromise Scanner for CVE-2019-19781

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

Bash tool used for proactive detection of malicious activity on macOS systems.