
timesketch
Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads



Panic button for protection against cold boot attacks

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Digital Forensics Intelligence Framework


CLI tools for forensic investigation of Windows artifacts

PowerShell script to mitigate CVE-2018-12038. The script takes a list of PC as input, gets their BitLocker encryption type remotely, and outputs a…

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Filesystem monitor tool for Linux/Android iOS/macOS

KQL Hunting for WinRAR CVE-2023-38831

This repository contains an academic and technical analysis of CVE-2023-34362, a critical SQL injection vulnerability affecting the MOVEit Transfer…

Real-time, container-based file scanning at enterprise scale

#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained