
RsWindowsThingies
Rust-based Windows forensic toolkit for real-time MFT monitoring, event log streaming, and channel enumeration, enabling live system analysis and…

Rust-based Windows forensic toolkit for real-time MFT monitoring, event log streaming, and channel enumeration, enabling live system analysis and…

OS X Auditor is a free Mac OS X computer forensics tool

Test Blue Team detections without running any attack.

Forensics artefact collection tool for systems running Microsoft Windows

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

DDWPasteRecon tool will help you identify code leak, sensitive files, plaintext passwords, password hashes. It also allow member of SOC & Blue Team…

Panic button for protection against cold boot attacks

A tool to assist with network-based hunting for GRU's Drovorub malware c2

PowerShell-based tool to detect and analyze exploitation attempts targeting CVE-2023-38831, aiding incident response and forensic investigations.

Rust-based tool to detect and mitigate CVE-2024-39930 ptrace exploitation, providing binary-level analysis and defensive countermeasures for Linux…

A powerful and flexible tool to apply active attacks for disrupting stegomalware

Small tool to play with IOCs caused by Imageload events

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

Basic log analysis tool to detect impossible travel via IP address geographic information

A tool to check if your lnd node was targeted by CVE-2019-12999

Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600

Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065

A tool to recover from ESXiArgs ransomware