
FLAIR
Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Patch for CVE-2026-12087, a critical heap overflow in Fortinet FortiOS SSL-VPN, deployed to production and validated by SecOps.

Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations

Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

Medium-interaction SSH honeypot deployment capturing real-world brute-force traffic, malware drops, and attacker behavior. Includes TTY session…