
FLAIR
Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Medium-interaction SSH honeypot deployment capturing real-world brute-force traffic, malware drops, and attacker behavior. Includes TTY session…

Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

Patch for CVE-2026-12087, a critical heap overflow in Fortinet FortiOS SSL-VPN, deployed to production and validated by SecOps.

Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations