
CyberPipe
An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe…

7-Zip CVE-2022-29072 Mitigation - CHM file - This script detects if the .chm file exists and removes it.

A temporary mitigation against copy_fail variant (copyfail2_electric_boogaloo) - Unprivileged Linux LPE via xfrm ESP-in-UDP MSG_SPLICE_PAGES no-COW…

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

Library and tools to access the Volume Shadow Snapshot (VSS) format

Forensic library and CLI toolkit for analyzing disk and file system images, recovering deleted data, generating timelines, and validating evidence…

Discord bot for mitigating the aCropalypse vulnerability (CVE-2023-21036, CVE-2023-28303) by retroactively deleting vulnerable images

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

This repository serves as a place for community created Targets and Modules for use with KAPE.

Collection of forensic tools

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Incident Response Forensic Framework

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Sysmon configuration file template with default high-quality event tracing

Monitoring Registry and File Changes in Windows

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)