
ToolShellFinder
Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.

Run on your ManageEngine server

A PowerShell Module Dedicated to Reverse Engineering

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865