
netlas-cookbook
The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Scan files or process memory for CobaltStrike beacons and parse their configuration

TCP/IP packet demultiplexer. Download from:

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

A list of covert channels and steganography/steganalysis resources (books, papers & tools)

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations

Blackout — The Official Blackout Public FAFO Repo.

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3…

Automation and Scaling of Digital Forensics Tools

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Repository of attack and defensive information for Business Email Compromise investigations

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…