
NTLMRawUnHide
NTLMRawUnhide.py is a Python3 script designed to parse network packet capture files and extract NTLMv2 hashes in a crackable format. The following…

NTLMRawUnhide.py is a Python3 script designed to parse network packet capture files and extract NTLMv2 hashes in a crackable format. The following…

Automagically extract forensic timeline from volatile memory dump

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Decodes PlugX traffic and encrypted/compressed artifacts

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

Real-world attack log analysis of CVE-2025-66478 (Next.js Server Actions RCE) with malware samples, attacker IP tracking, and container security…

Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.