

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

E-Mail Header Analyzer

Telegram intelligence collection tool for researchers and investigators. Scrapes groups, messages, media, and user data with OCR, Elasticsearch…

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…


Recognizing the most likely APT groups responsible for an incident

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

This repository contains a list of new remediation scripts.

Defanged Indicator of Compromise (IOC) Extractor.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Bash tool used for proactive detection of malicious activity on macOS systems.

Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues.

IoC determination for exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.

Analysis and Representation of Graphs of Suspicious Operations (Analyse et Représentation des Graphes des Opérations Suspectes)

Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771