
ALPC-Enumerator
A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A list of cyber-chef recipes and curated links

Malcom - Malware Communications Analyzer

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

🐍 High-performance, multi-threaded YARA & IOC scanner

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Visually inspect and force decode YARA and regex matches found in both binary and text data with colors. Lots of colors.

Python tool and library to help analyze files during malware triage and analysis.

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

VirusTotal Wanna Be - Now with 100% more Hipster

Cortex: a Powerful Observable Analysis and Active Response Engine

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Curated collection of detection rules and IOCs extracted from DFIR engagements and malware analyses to support threat hunting, incident response, and…

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

CVE-2021-44228 DFIR Notes