
FLAIR
Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Repository of attack and defensive information for Business Email Compromise investigations

Scan your Windows computer for known vulnerable or malicious drivers.

Proof-of-concept telemetry collector for Windows LDAP client activity via ETW, logging structured events to Event Viewer with a Sentinel parser for…

Safe read-only version checker + Sigma rule for Redis CVE-2026-23479 (authenticated use-after-free → RCE). Find exposed instances, patch…

CVE-2025-33073 Research writeup

Example InSpec profile to detect presence of a malicious rest-client gem (CVE-2019-15224)

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…