
factual-rules-generator
Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Indicator of Compromise Scanner for CVE-2019-19781

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

GUI for Volatility forensics tool written in PyQT5

Linux Persistence Detection, Hunting and Artifact Collection script

Challenge handouts, source code, and solutions for UofTCTF 2025

Release of the sandy framework.

Timestomp Tool to flatten MAC times with a specific timestamp


Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity

AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and generates…

A tool to parse Firefox and Chrome HSTS databases into forensic artifacts!

Automated YARA rule generation from the Cert Central compromised certificate database.


Experimental Linux strace LLM agent