
IRM
Incident Response Methodologies 2022

Incident Response Methodologies 2022

A repository to share publicly available Velociraptor detection content

the ps utility, with an eBPF twist and container context

DShield Sensor Log Collection with ELK

Scan your Windows computer for known vulnerable or malicious drivers.

Generates portable SystemTap kernel modules to mitigate CVE-2013-2094 on Enterprise Linux systems, with automated build and deployment scripts for…

a guard that blocks catastrophic agent actions

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Code canaries to quickly triage hallucinated ('slop') vulnerability reports

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

Filesystem scanner for Log4Shell (CVE-2021-44228) and related CVEs. Detects vulnerable JAR files via hash matching and class presence. Runs…

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

IOC scanner for agentic AI coding tools — detects Mini Shai-Hulud, Gemini CLI RCE, Cursor CVE-2026-26268, and DPRK PromptMink.

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

a fast check, if your server could be vulnerable to CVE-2021-44228

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.