
MozCache
Simple shell script to perform forensic analysis of the Mozilla-Browsers cache (Firefox, Iceweasel and Seamonkey).

Simple shell script to perform forensic analysis of the Mozilla-Browsers cache (Firefox, Iceweasel and Seamonkey).

The Multiplatform Linux Sandbox

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

Crack iOS Restriction Passcodes with Python

AI 驱动的 SOC 仿真平台

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

Crack ios Restriction PassCode in Python

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…

PDQ package for detecting CVE-2022-30190 (Follina) vulnerability by scanning registry keys (ms-msdt, search-ms) across Windows endpoints, enabling…

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Script to parse Aircrack-ng captures into a SQLite database and extract useful information like handshakes, MGT identities, interesting relations…

Materials for Windows Malware Analysis training (volume 1)

Cosa Nostra, a FOSS graph based malware clusterization toolkit.

Enumerate various traits from Windows processes as an aid to threat hunting

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252