
Persistnux
Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Finding secrets in kernel and user memory

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Utility for recovering ES File Explorer encrypted files (.eslock)

FAT filesystems explore, extract, repair, and forensic tool

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…

Artifact collection tool for *nix systems

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Detection Script for MongoBleed Exploitation

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs