
ADRecon
PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Analysis and cleanup guide for BadBox malware on Allwinner H713 Android projectors: ADB access, infection proof, firmware backup, dropper removal,…

Filesystem monitor tool for Linux/Android iOS/macOS

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

"A single malicious packet can own your device." — Android Security Team, Nov 2025

Android CVE-2024-0044, 43093, 23706 zafiyet analizi ve PoC lab ortamı

A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.

Extract registry and NTDS secrets from local or remote disk images

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

Operational exploit for CVE-2025-61882 in Oracle E-Business Suite, with research artifacts for defensive validation, detection engineering, incident…

Python PoC and exploit for CVE-2026-59310, a VMware vCenter syslog path traversal leading to unauthenticated root RCE via cron injection, with…

Provides mitigation and detection guidance for CVE-2026-8388, including indicators of compromise and remediation steps for security teams.

Collection of Detection, Fix, and exploit for CVE-2024-3094