
python-exe-unpacker
A helper script for unpacking and decompiling EXEs compiled from python code.

A helper script for unpacking and decompiling EXEs compiled from python code.

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Collects comprehensive triage data from macOS for incident response, including system logs, file listings, browser data, shell history, and…

YARA rule and python script to detect potential exploits for the CVE-2026-21509 vulnerability in MS Office

CVE-2026-31431 Copy Fail Linux kernel vulnerability detection script

A python script developed to process Windows memory images based on triage type.

My musings with PowerShell

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR



Python script that will extract all saved passwords from your google chrome database on windows only

Decodes PlugX traffic and encrypted/compressed artifacts

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Extracts nanocore sample from compile AutoIT script

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents