
packetsifterTool
PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Script to remove homoglyphs and zero-width characters to allow for safe distribution of documents from anonymous sources.

Automates incident response tasks via Carbon Black Response API: file/registry deletion, process killing, sensor isolation, binary collection, and…

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

Windows link file (shortcuts) examiner

Search and extract blob files on the Ethereum Blockchain network

Online Reverse Enginerring viewer

PETriage: A symbol-unified PE file reader for triage, built for multi-platform and multi-interface use.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Utility for recovering ES File Explorer encrypted files (.eslock)

XZ Backdoor Extract(Test on Ubuntu 23.10)

Universal signature generation for any system function from all Windows Builds using Winbindex

Custom BTRFS repair tools for severe extent tree corruption where btrfs check --repair fails (segfault, loop, or deadlock)

Comprehensive analysis of CVE-2022-30190 (Follina MSDT vulnerability) with IOCs, detection rules for SIEMs/EDR, YARA signatures, mitigation scripts,…

Audit Guide for the Citrix ADC Vulnerability CVE-2019-19871. Collected from multiple sources and threat assessments. Will be updated as new methods…

X-Ways Acropalypse extension detects CVE-2023-21036 in common images