
ma2tl
macOS forensic timeline generator using the analysis result DBs of mac_apt

macOS forensic timeline generator using the analysis result DBs of mac_apt

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Volatility Explorer Suit (volatility 3)

bad stuffs by bad guys

A small utility to translate NTDS.dit files to SQLite format.

A simple, reliable and reasonably fast network capture analyzer.


Python script for carving Bitlocker VMK keys

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Hash database builder and reverse lookup tool — SHA256, RIPEMD160, Keccak256, BLAKE3 and more


A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282,…


Recognizing the most likely APT groups responsible for an incident