
FarsightAD
PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

ToolShell scanner - CVE-2025-53770 and detection information

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

Detecting vulnerabilities like CVE-2024-0762, particularly in UEFI firmware, is quite challenging due to the low-level nature

A low to medium interaction honeypot.

Cortex: a Powerful Observable Analysis and Active Response Engine

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

This repository contains a list of new remediation scripts.

Botnet command & control monitor

Automated, Collection, and Enrichment Platform

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

KQL Hunting for WinRAR CVE-2023-38831