
Microsoft-Extractor-Suite
A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Automate the creation of a lab environment complete with security tooling and logging best practices

Automation and Scaling of Digital Forensics Tools

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Repository of attack and defensive information for Business Email Compromise investigations

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

A centralized and enhanced memory analysis platform

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

Data from a BRAWL Automated Adversary Emulation Exercise

Blue Team detection lab created with Terraform and Ansible in Azure.

Toolkit for decoding, inspecting, and modifying UEFI firmware volumes and variable stores. Supports secure boot certificate enrollment, PE binary…

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

This is an incident response playbook we created for the Vercel April 2026 compromise