
chainsaw
Rapidly Search and Hunt through Windows Forensic Artefacts

Rapidly Search and Hunt through Windows Forensic Artefacts

Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

🚨 Threat intel & incident response research on SharePoint "ToolShell" RCE zero-day (CVE-2025-53770). 🕵️♂️ Covers root-cause deserialization flaws,…


Software to identify the different types of hashes -

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack

Step-by-step walkthrough of a LetsDefend SOC342 lab analyzing CVE-2025-53770 SharePoint ToolShell auth bypass and RCE, including attack chain,…

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

Advanced SMB Honeypot: CVE-2025-33073 Research & Implementation

Real-world attack log analysis of CVE-2025-66478 (Next.js Server Actions RCE) with malware samples, attacker IP tracking, and container security…

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…


Python-based scanner for CVE-2025-55182 indicators of compromise. Checks filesystem paths, processes, systemd services, cron persistence, and…

Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability