
ZeroPoint
This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

This is a bash script focus on hardening linux. This is a custom think of windows defender but unlike of their privacy issue. User can feel freedom…

Rust-based Windows forensic toolkit for real-time MFT monitoring, event log streaming, and channel enumeration, enabling live system analysis and…

This is a repo for fetching Applocker event log by parsing the win-event log

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…


Some tools to help mitigating Apache Log4j 2 CVE-2021-44228

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Top DNS Measurement for Bro

** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…

Mapping Corelight or Zeek data to Elastic Common Schema fields

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Mapping Corelight or Zeek data to Elastic Common Schema logs

PowerShell script to scan Windows Event Logs for CVE-2020-1472 indicators (events 5827-5831), export to CSV, and generate Excel pivot tables for…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.