
Remote-Access-Trojan-Database
A database of RAT collected from Internet

A database of RAT collected from Internet

CVE-2021-1675 Detection Info

Capturing, analysing and responding to cyber attacks

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Automated forensic script hunting for cve-2019-19781

Fast and accurate AI powered file content types detection

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.


:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

A tool that removes traces of executed applications on Windows OS.

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Malware Configuration And Payload Extraction

TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Asclepius validates backup integrity by restoring files and actively testing their recoverability. Instead of trusting metadata, it attempts to parse…

Automatic analysis of SWF files based on some heuristics. Extensible via plugins.