
tscopy
Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

android location service cache dumper

Recognizing the most likely APT groups responsible for an incident

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

Cortex: a Powerful Observable Analysis and Active Response Engine

This repository contains a list of new remediation scripts.

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

[Linux] Two Privilege Escalation techniques abusing sudo token

Python script that will extract all saved passwords from your google chrome database on windows only

Parsing Ramnit's traffic

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.