
dfir-orc
Forensics artefact collection tool for systems running Microsoft Windows

Forensics artefact collection tool for systems running Microsoft Windows

Powershell module for VMWare vSphere forensics

🗒️ A [work-in-progress] collection for interview questions for Information Security roles

Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

Rapidly Search and Hunt through Windows Forensic Artefacts

Lua-based Wireshark postdissector that decrypts and parses Ubiquiti AirMAX/RouterBoard 802.11 vendor IEs into filterable fields.

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

A python script developed to process Windows memory images based on triage type.

A Windows kernel dump C++ parser library with Python 3 bindings.

Visualize the virtual address space of a Windows process on a Hilbert curve.

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

An OSINT / digital forensics tool built in Python

Digital Forensics Intelligence Framework

Enumerate various traits from Windows processes as an aid to threat hunting

Basic log analysis tool to detect impossible travel via IP address geographic information


A tool to use novel locations to extract metadata from Office documents.