
EntraTrace
Defensive research tool that documents observable API endpoints and user agents of offensive tooling targeting Microsoft Entra ID, supporting…

Defensive research tool that documents observable API endpoints and user agents of offensive tooling targeting Microsoft Entra ID, supporting…


A network sniffer that logs all DNS server replies for use in a passive DNS setup


A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

analyze a web-based network traffic 🕶 to detect central command and control servers

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Artifact collection tool for *nix systems

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

DDWPasteRecon tool will help you identify code leak, sensitive files, plaintext passwords, password hashes. It also allow member of SOC & Blue Team…

Basic log analysis tool to detect impossible travel via IP address geographic information

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Forensics artefact collection tool for systems running Microsoft Windows

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

Real Time Threat Monitoring Tool