
macos-collector
macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Linux Persistence Detection, Hunting and Artifact Collection script

Script to parse Aircrack-ng captures into a SQLite database and extract useful information like handshakes, MGT identities, interesting relations…

cve-2026-46331-audit script

cPanel CVE-2026-41940 nuclear.x86 Security Audit & Cleanup Script

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

CVE-2026-31431 Copy Fail Linux kernel vulnerability detection script

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Real-world incident response for CVE-2025-55182 (React2Shell) — script injection, server remediation, and post-incident report

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…

YARA rule and python script to detect potential exploits for the CVE-2026-21509 vulnerability in MS Office