
Analysis
Hands-on analysis of common APT attack techniques, focused on how they show up in logs and how defenders can realistically detect them.

Hands-on analysis of common APT attack techniques, focused on how they show up in logs and how defenders can realistically detect them.

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

gundog - guided hunting in Microsoft Defender

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

AI-powered Windows diagnostic & auto-repair tool using Google Gemini. Detect crashes, optimize performance, scan for malware, and generate PowerShell…

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

High fidelity defensive security lab simulating a DoD aligned enterprise network with Active Directory, VLAN segmentation, STIG based hardening,…

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…

PowerShell-based scanner to detect Log4j CVE-2021-44228 vulnerability by searching directories and log files for exploitation indicators.

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

PowerShell module for Office 365 and Azure log collection

Powershell module for VMWare vSphere forensics

An open-source, single-script CVE scanner for RMM-managed fleets. Pure PowerShell 7 — joins your RMM software inventory against NVD, CISA KEV, EPSS…

Evtx Log (xml) Browser

You didn't think I'd go and leave the blue team out, right?