
Simple-Live-Data-Collection
Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

Programmable packet inspection engine with NIDS, DNS classification, frequency analysis, and auto-regex generation. Supports Python/Ruby/Java/Lua…

Static analysis tool for investigating potentially malicious Microsoft Excel files, extracting metadata, macros, and embedded objects to aid digital…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Basic log analysis tool to detect impossible travel via IP address geographic information

Centralized IoC scanner that deploys Loki across endpoints, collects detection results, and parses logs into CSV for incident response and forensic…

Graph-first network traffic visualizer for live capture and PCAP replay with checkpoint diffing, path tracing, and Wireshark-style display filters…

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…


Browser-based tool for visual steganography detection via LSB analysis on digital images, enabling forensic examination and stegomalware…

JAR analysis tool for exploring, searching, and extracting specific classes from large JAR files with bytecode search, multi-selection extraction,…

Contains tools to perform malware and forensic analysis in Memory

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

IOC feed and analysis toolkit for EITest campaigns, featuring C2 data decryption, victim payload decoding, and sinkhole log processing for threat…

Local Linux binary analysis tool. Zero cloud. Zero root. See exactly what a binary does before you run it.