
MemProcFS-Analyzer
Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Powershell to mitigate CVE-2022-29072

Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

PowerShell script to mitigate CVE-2018-12038. The script takes a list of PC as input, gets their BitLocker encryption type remotely, and outputs a…

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Hands-on analysis of common APT attack techniques, focused on how they show up in logs and how defenders can realistically detect them.

Run on your ManageEngine server

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

gundog - guided hunting in Microsoft Defender

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…