
ReClass.NET
More than a ReClass port to the .NET platform.

More than a ReClass port to the .NET platform.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Python Decoders for Common Remote Access Trojans

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

A portable C# utility for enumerating local and remote windows sessions

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery…

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

This repository provides production-ready detection engineering content for **CVE-2025-25257**, a pre-authentication SQL Injection vulnerability in…

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack

OpenIOC rules to facilitate hunting for indicators of compromise

"A single malicious packet can own your device." — Android Security Team, Nov 2025


CVE-2017-0144

Technical analysis and detection guidance for CVE-2025-53770, a critical unauthenticated RCE vulnerability in Microsoft SharePoint Server exploited…