
Meerkat
A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Collection of some easy of use tools - in powershell.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.


PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Automate the creation of a lab environment complete with security tooling and logging best practices

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.