
ADRecon
PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Forensics artefact collection tool for systems running Microsoft Windows

Cortex: a Powerful Observable Analysis and Active Response Engine

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Repository documenting CVE-2019-19781 with a scanner, honeypot, and DFIR notes for Citrix ADC vulnerability detection and incident response.

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Automates Linux swap analysis to extract user credentials, web form data, WiFi keys, and HTTP authentication during post-exploitation or forensic…

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework


A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️

Defanged Indicator of Compromise (IOC) Extractor.


Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…