
Skadi
Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Rules generated from our investigations.

An agent to hotpatch the log4j RCE from CVE-2021-44228.

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…

A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from…

Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with…

Enumerate various traits from Windows processes as an aid to threat hunting

Ransomware decryption and script deobfuscation utilities from a threat intelligence team, designed for incident responders and malware analysts.

Automagically extract forensic timeline from volatile memory dump

Data from a BRAWL Automated Adversary Emulation Exercise

Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group

A canary designed to minimize the impact from certain Ransomware actors

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

A community‑driven cybersecurity knowledge base with 400+ notes, mind‑maps, and cheat‑sheets – built from first principles. Ideal for students, SOC…

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

IoCs and YARA rules from Threatray's Threat Research