
physical-analyzer-scripts
Cellebrite Physical Analyzer python scripts to aid analysts with extended functionality

Cellebrite Physical Analyzer python scripts to aid analysts with extended functionality

History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit

Collection of some easy of use tools - in powershell.

Scripts for extracting useful information from infected memory dumps


A python script for digital image steganography using Fast Fourier Transform.

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

CVE-2021-44228 DFIR Notes

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Shell Companies Inside Apple's Privacy Relay

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Demostracion educativa de mitigacion de CVE-2026-68820: Use-After-Free en afd.sys de Windows.

React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트


Proof-of-concept script that analyzes Windows memory dumps to recover visited Tor onion services, bypassing Tor Browser's anonymity by exploiting…