
log4j
Repo containing all info, scripts, etc. related to CVE-2021-44228

Repo containing all info, scripts, etc. related to CVE-2021-44228


Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282,…

Some tools to help mitigating Apache Log4j 2 CVE-2021-44228


A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…



The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

My Citrix ADC NetScaler CVE-2019-19781 Vulnerability DFIR notes.



Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Searches For Threat Hunting and Security Analytics

Parses Snaffler output file and generate beautified outputs.

Database Driven DNS Server with a Web UI

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…