
ppid-spoofing
Scripts for performing and detecting parent PID spoofing

Scripts for performing and detecting parent PID spoofing

These are the source codes of the Python scripts to apply the temporary protection against the CVE-2022-30190 vulnerability (Follina)

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

a fast check, if your server could be vulnerable to CVE-2021-44228

Blue Team detection lab created with Terraform and Ansible in Azure.

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…

Proof-of-concept reproducing CVE-2021-22681's hardcoded-key flaw and validating a per-device mutual TLS/CRL fix over simulated EtherNet/IP, with IEC…

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Windows Elevation of Privilege Vulnerability (SeriousSAM)

Shell script to detect CVE-2026-31431 (Copy Fail) exposure and mitigations on Linux systems: kernel check, module state, boot params, AF_ALG…

PowerShell script to detect and remediate CVE-2023-23397 privilege escalation vulnerability in Microsoft Outlook and Exchange environments.

Forensic triage toolkit for Citrix NetScaler devices, featuring a Dissect-based IOC scanner for webshells, timestomping, and suspicious binaries,…