
misp-wireshark
Lua plugin to extract data from Wireshark and convert it into MISP format

Lua plugin to extract data from Wireshark and convert it into MISP format

A tool to use novel locations to extract metadata from Office documents.

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Volatility plugin to extract X screenshots from a memory dump

Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

Burp Suite extension for extracting metadata from files

Automated YARA rule generation from the Cert Central compromised certificate database.

bash CLI trainer — 30 levels from ls to privilege escalation

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

Universal signature generation for any system function from all Windows Builds using Winbindex

Extracts nanocore sample from compile AutoIT script

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

A lightweight eBPF program to monitor file creation and modification events on Linux. This tool leverages eBPF (Extended Berkeley Packet Filter) to…

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack