
MemProcFS-Analyzer
Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)


This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…


Hands-on analysis of common APT attack techniques, focused on how they show up in logs and how defenders can realistically detect them.

Run on your ManageEngine server

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Automate the creation of a lab environment complete with security tooling and logging best practices

gundog - guided hunting in Microsoft Defender

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.
