
Meerkat
A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

A PowerShell Module Dedicated to Reverse Engineering

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Run on your ManageEngine server