
refinery
Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Visualize the virtual address space of a Windows process on a Hilbert curve.

A collection of malware samples caught by several honeypots i manage

Enumerate various traits from Windows processes as an aid to threat hunting

Basic log analysis tool to detect impossible travel via IP address geographic information


A tool to use novel locations to extract metadata from Office documents.

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

Public repository of Sigma and YARA rules created by Synacktiv

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

Fingerprint SSH clients and servers.

A Zeek STUN protocol analyzer based on Spicy.

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.