
Douglas-042
Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

Run on your ManageEngine server

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

A PowerShell Module Dedicated to Reverse Engineering

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks