
z9
Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.


A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771


Hands-on analysis of common APT attack techniques, focused on how they show up in logs and how defenders can realistically detect them.

Automate the creation of a lab environment complete with security tooling and logging best practices

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

gundog - guided hunting in Microsoft Defender

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Run on your ManageEngine server
