
factual-rules-generator
Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…


Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

Blue Team detection lab created with Terraform and Ansible in Azure.

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

Current links from the OSINT Inception start-me project

Step-by-step walkthrough of detecting and analyzing CVE-2024-24919 exploitation using a SIEM platform, including traffic analysis, IOC documentation,…

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Re-play Security Events