
DFIR-LABS
Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Bash script to assess Linux host exposure to CVE-2026-31431, check kernel module status, apply mitigation by blocking algif_aead, and update kernel…

A Simple Ransomware Vaccine

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

A cross platform parser for Apple UnifiedLogs!

A Simple Log4j Indicator of Compromise Linux Detector

CVE-2025-20352 Research writeup

The CVE-2022-30190-follina Workarounds Patch

A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.

Contains a simple yara rule to hunt for possible compromised KeePass config files

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have…

Simple honeypot for CVE-2024-3400 Palo Alto PAN-OS Command Injection Vulnerability

A simple bash script to check for evidence of compromise related to CVE-2024-3400

test for the ioc described for FG-IR-22-398

A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability

A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…