
LDAPMon
Proof-of-concept telemetry collector for Windows LDAP client activity via ETW, logging structured events to Event Viewer with a Sentinel parser for…

Proof-of-concept telemetry collector for Windows LDAP client activity via ETW, logging structured events to Event Viewer with a Sentinel parser for…

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Repository of attack and defensive information for Business Email Compromise investigations

Scan your Windows computer for known vulnerable or malicious drivers.

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

CVE-2025-33073 Research writeup

Example InSpec profile to detect presence of a malicious rest-client gem (CVE-2019-15224)

Safe read-only version checker + Sigma rule for Redis CVE-2026-23479 (authenticated use-after-free → RCE). Find exposed instances, patch…