
conti-ransomware-writeup
Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Documentation and scripts to properly enable Windows event logs.

Evtx Log (xml) Browser

Python ctypes wrapper for Event Tracing for Windows (ETW) enabling session control, event capture, and custom callbacks for security monitoring and…

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Rust-based Windows forensic toolkit for real-time MFT monitoring, event log streaming, and channel enumeration, enabling live system analysis and…

Windows honeypot using ProjFS to project decoy files that trigger Event Log and desktop alerts when accessed, with SMB remote session logging for…

Endpoint detection & Malware analysis software

An open-source, single-script CVE scanner for RMM-managed fleets. Pure PowerShell 7 — joins your RMM software inventory against NVD, CISA KEV, EPSS…

An Active Defense and EDR software to empower Blue Teams

ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…

Anti-keylogger/anti-rat application for Windows

This is a repo for fetching Applocker event log by parsing the win-event log

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

A python script developed to process Windows memory images based on triage type.

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003