
routeros-scanner
Tool to scan for RouterOS (Mikrotik) forensic artifacts and vulnerabilities.

Tool to scan for RouterOS (Mikrotik) forensic artifacts and vulnerabilities.

Defensive research tool that documents observable API endpoints and user agents of offensive tooling targeting Microsoft Entra ID, supporting…

Forensics artefact collection tool for systems running Microsoft Windows

Basic log analysis tool to detect impossible travel via IP address geographic information

analyze a web-based network traffic 🕶 to detect central command and control servers

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Real Time Threat Monitoring Tool


A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

Rust-based Windows forensic toolkit for real-time MFT monitoring, event log streaming, and channel enumeration, enabling live system analysis and…

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…