
XWFAcropalypse
X-Ways Acropalypse extension detects CVE-2023-21036 in common images

X-Ways Acropalypse extension detects CVE-2023-21036 in common images
Repository containing the compromised certificate seen in recent CVE-2022-30190 (Follina) attacks.

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

My Citrix ADC NetScaler CVE-2019-19781 Vulnerability DFIR notes.

SkypeACLKeyGen.exe analysis for hacking team



Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Finding secrets in kernel and user memory

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

WhatsApp Forensic Tool

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.