
DAMM
Differential Analysis of Malware in Memory

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Indicator of Compromise Scanner for CVE-2019-19781

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Kirjuri is a web application for managing cases and physical forensic evidence items.

Tracking history of USB events on GNU/Linux

ThePhish: an automated phishing email analysis tool

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Regipy is an os independent python library for parsing offline registry hives

Digital forensic acquisition tool for Windows based incident response.

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".


Detection Script for MongoBleed Exploitation

Automated forensic script hunting for cve-2019-19781