
dfir-orc
Forensics artefact collection tool for systems running Microsoft Windows

Forensics artefact collection tool for systems running Microsoft Windows

A tool to use novel locations to extract metadata from Office documents.

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )


CVE-2017-0144

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.


Technical analysis and detection guidance for CVE-2025-53770, a critical unauthenticated RCE vulnerability in Microsoft SharePoint Server exploited…

Universal signature generation for any system function from all Windows Builds using Winbindex

Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table,…

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

A wireshark plugin to instrument ETW