
MrHandler
SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Incident Response collection and processing scripts with automated reporting scripts

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Easy-to-use live forensics toolbox for Linux endpoints

Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)

Detection Script for MongoBleed Exploitation

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

An event-driven network monitoring platform that performs live packet capture (Npcap), low-latency traffic analytics, and unsupervised threat…

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Android Logs Events And Protobuf Parser

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…

LDAP Watchdog: A real-time linux-compatible LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications,…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.