
AfterLife
Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706…

Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706…
Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Agentic memory for CTI in Python — STIX knowledge graphs, threat-actor alias resolution, offline-first RAG, MCP server for Claude Code and LangChain…

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during…

A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability

Python script to check Palo Alto firewalls for CVE-2024-3400 exploit attempts

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Python Decoders for Common Remote Access Trojans

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Regipy is an os independent python library for parsing offline registry hives

A python script developed to process Windows memory images based on triage type.

Python ctypes wrapper for Event Tracing for Windows (ETW) enabling session control, event capture, and custom callbacks for security monitoring and…

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

A Windows kernel dump C++ parser library with Python 3 bindings.

A python package for use in generating fake data for SOC and security automation.

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…