
autopsy
Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Distributed & real time digital forensics at the speed of the cloud

Filesystem monitor tool for Linux/Android iOS/macOS

Defanged Indicator of Compromise (IOC) Extractor.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Full-node Bitcoin client that validates transactions and blocks on the peer-to-peer network, with integrated wallet, cryptographic security, and…

Re-play Security Events

Awesome list of keywords and artifacts for Threat Hunting sessions


android location service cache dumper

Add POST body excerpt to Bro's HTTP log

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

UNIX-like reverse engineering framework and command-line toolset.

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).