
PersistenceSniper
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

Hunt down social media accounts by username across social networks

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Rapidly Search and Hunt through Windows Forensic Artefacts

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

OSINT tool researched and designed to hunt down IG handles

eBPF-based Linux security monitor and threat hunter providing chronologically ordered, container-aware events with on-host correlation for incident…

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

Detect Linux rootkits which use signals to elevate process privileges.

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…


Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table,…

Contains a simple yara rule to hunt for possible compromised KeePass config files