
AzureHunter
A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.


Repository documenting CVE-2019-19781 with a scanner, honeypot, and DFIR notes for Citrix ADC vulnerability detection and incident response.

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Forensics artefact collection tool for systems running Microsoft Windows

A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️

Artifact collection tool for *nix systems

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Automates Linux swap analysis to extract user credentials, web form data, WiFi keys, and HTTP authentication during post-exploitation or forensic…

Defanged Indicator of Compromise (IOC) Extractor.


A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Cortex: a Powerful Observable Analysis and Active Response Engine