
DFIR4vSphere
Powershell module for VMWare vSphere forensics
cloud-infrastructure-securityconfiguration-auditingdefensive-tools+5
185

Powershell module for VMWare vSphere forensics

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781

Multi-host UFW firewall dashboard — explains rules in plain English, detects security gaps, and provides connection diagnostics

Daemon to ban hosts that cause multiple authentication errors

Incident Response collection and processing scripts with automated reporting scripts