
AzureHunter
A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

gundog - guided hunting in Microsoft Defender

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Run on your ManageEngine server