
SuperMem
A python script developed to process Windows memory images based on triage type.
digital-forensicsforensicsincident-response+2
267

A python script developed to process Windows memory images based on triage type.

Kernel-mode filter driver that monitors ConDrv traffic to detect mimikatz execution in real-time, logging detection events via ETW for incident…

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Hands-on detection research repository documenting how APT techniques appear in logs, with practical detection logic, Splunk queries, and Sigma rules…

End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack…