
xz-cve-2024-3094
Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

A scanner that files with compromised or untrusted code signing certificates written in python.

Source code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

Total Commander FTP Password Recovery Tool for Python allows you to decrypt the FTP account password information for all Total Commander versions…

Source code for the book "Violent Python" by TJ O'Connor. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

NetworkAssessment: Network Compromise Assessment Tool

Volatility plugin to extract X screenshots from a memory dump

This is a repo for fetching Applocker event log by parsing the win-event log

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Hashes for vulnerable LOG4J versions

Windows link file (shortcuts) examiner

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

A tool that detect if your node has been victim of the invalid funding tx attack.

The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Information on the Windows Spooler vulnerability - CVE-2021-1675; CVE 2021 34527

Detection of malicious VHD files for CVE-2025-24985