
ptcpdump
eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Linux Persistence Detection, Hunting and Artifact Collection script

System-based incident response tracking application for managing large-scale DFIR cases, with import/export, task workflows, and artifact tracking…

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Labtainers: A Docker-based cyber lab framework


Automate the creation of a lab environment complete with security tooling and logging best practices

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

OS X Auditor is a free Mac OS X computer forensics tool

A small utility to translate NTDS.dit files to SQLite format.

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

E-Mail Header Analyzer