
OffsetInspect
PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA,…

PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA,…

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Evtx Log (xml) Browser

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

My musings with PowerShell

A PowerShell Module Dedicated to Reverse Engineering

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Automated detection, assessment, and remediation toolkit for SharePoint CVE-2025-53770 (CVSS 9.8). Includes PowerShell scripts to verify patch…

PowerShell script to scan Windows Event Logs for CVE-2020-1472 indicators (events 5827-5831), export to CSV, and generate Excel pivot tables for…

Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

Run on your ManageEngine server