
whodunit
Recognizing the most likely APT groups responsible for an incident
digital-forensicsincident-responsethreat-intelligence

Recognizing the most likely APT groups responsible for an incident

The CVE-2022-30190-follina Workarounds Patch

A lightweight eBPF program to monitor file creation and modification events on Linux. This tool leverages eBPF (Extended Berkeley Packet Filter) to…

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

volatility explorer (volatility 2)

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…