
lpc_sniffer_tpm
A low pin count sniffer for ICEStick - targeting TPM chips

A low pin count sniffer for ICEStick - targeting TPM chips

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

Android Connections Forensics

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Cellebrite Physical Analyzer python scripts to aid analysts with extended functionality

Lack of argument sanitization leading to password leakage in Ghostscript PDF versions up to 10.05.0.

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

Forensic evidence dossier for Operation Black Hole - Investigating fraudulent Falla app ecosystem (TRON blockchain, admin panel exposure,…

Python program to steganography files into images using the Least Significant Bit.