
CVE-2021-36934-DLL-Hijacking-DFIR-Investigation
DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

Investigation of CVE-2024-4577 exploitation and AsyncRAT deployment with DFIR artifacts, IoCs, and detection guidance.

Static vulnerability findings tracker with parallel search across 11 CVE databases, EPSS enrichment, CISA KEV badges, coordinated disclosure…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…


This repository contains a list of new remediation scripts.

Just my findings of malwares

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Collects and organizes malware indicators of compromise (IOCs) for rapid threat detection, incident response, and actionable intelligence sharing.

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

A repository of sysmon configuration modules

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Detect Tactics, Techniques & Combat Threats

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Collection of private Yara rules.

Recognizing the most likely APT groups responsible for an incident

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.