
ADRecon
PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

Volatility 3 ported to Rust. Same output, much faster.

ESF modular ingestion tool for development and research.

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

Kernel-runtime defense framework for AF_ALG vulnerabilities, featuring eBPF socket tracing, Ansible hardening, and a crypto auditor for drift…

Evtx Log (xml) Browser

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

The TTPForge is a Cybersecurity Framework for developing, automating, and executing attacker Tactics, Techniques, and Procedures (TTPs).

Digital Forensics Intelligence Framework

Detection of Manjusaka C2 framework

OWASP Honeypot, Automated Deception Framework.

Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Detection framework for CVE-2025-32463 sudo privilege escalation vulnerability. Provides real-time monitoring, forensic analysis, and SIEM…

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

Multi-layer security framework for AI agent ecosystems. Provides pre-installation skill auditing, file integrity monitoring, runtime protection, and…

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…