
NorkNork
Powershell Empire Persistence finder

Powershell Empire Persistence finder

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Detection and analysis toolkit for CVE-2026-31431 Linux LPE, providing Python and PowerShell scanners, YARA rules, and forensic analysis for active…

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

AI-powered Windows diagnostic & auto-repair tool using Google Gemini. Detect crashes, optimize performance, scan for malware, and generate PowerShell…

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

Timestomp Tool to flatten MAC times with a specific timestamp

A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…

PowerShell module for Office 365 and Azure log collection

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Powershell module for VMWare vSphere forensics