
macos-collector
macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database

Mapping Corelight or Zeek data to Elastic Common Schema logs

Mapping Corelight or Zeek data to Elastic Common Schema fields

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

CVE-2026-31431 Copy Fail Linux kernel vulnerability detection script

This is the office check script provided by cPanel for all the users who are using cPanel

CVE-2026-41940 cPanel/WHM auth bypass IOC scanner — fixes false positives in upstream detection script, adds log cross-correlation

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

This is a bash script focus on hardening linux. This is a custom think of windows defender but unlike of their privacy issue. User can feel freedom…

Detection content for CVE-2026-22557 — UniFi Network Application unauthenticated path traversal (CVSS 10.0). Includes YARA, Sigma, KQL, Splunk SPL,…

A script that helps you understand why your E-Mail ended up in Spam

Detection Script for MongoBleed Exploitation

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

Add POST body excerpt to Bro's HTTP log

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771