
security-onion
Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Library and tools to access the Windows New Technology File System (NTFS)

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Automates Linux swap analysis to extract user credentials, web form data, WiFi keys, and HTTP authentication during post-exploitation or forensic…

Linux kernel driver for physical memory acquisition, enabling read access to any physical address including reserved memory and memory holes, with…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Linux Memory Cryptographic Keys Extractor

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

NeuroCore is a native macOS application that visualizes the internal structure of binary files using a Hilbert Curve mapping and Shannon Entropy…

Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)

Medium-interaction SSH honeypot deployment capturing real-world brute-force traffic, malware drops, and attacker behavior. Includes TTY session…