
ptcpdump
eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Linux Persistence Detection, Hunting and Artifact Collection script

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Provides supplemental files and Debian package sources for a specialized Linux distro focused on malware analysis, reverse engineering, and digital…

Powershell module for VMWare vSphere forensics

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database

One-shot detection and remediation for cPanel/WHM servers compromised via CVE-2026-41940, including IOC checks, malware cleanup, C2 blocking, and…

Automate the creation of a lab environment complete with security tooling and logging best practices

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package