
Honeypot-for-CVE-2025-59287-WSUS
Defensive PoC decoy for CVE-2025-59287 (WSUS) - emulates WSUS endpoints, captures request bodies and metadata, saves evidence for forensic analysis,…

Defensive PoC decoy for CVE-2025-59287 (WSUS) - emulates WSUS endpoints, captures request bodies and metadata, saves evidence for forensic analysis,…

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Automated, Collection, and Enrichment Platform

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

Windows EDR with Gene-based detection engine, real-time artifact collection, Sysmon integration, and REST API for managing endpoints, rules, and…

Centralized IoC scanner that deploys Loki across endpoints, collects detection results, and parses logs into CSV for incident response and forensic…

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

PDQ package for detecting CVE-2022-30190 (Follina) vulnerability by scanning registry keys (ms-msdt, search-ms) across Windows endpoints, enabling…

Easy-to-use live forensics toolbox for Linux endpoints

Distributed & real time digital forensics at the speed of the cloud