
CitrixNetscalerAnalysis
🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781

🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.


An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Digital forensic acquisition tool for Windows based incident response.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

X-Ways Acropalypse extension detects CVE-2023-21036 in common images

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…