
Sandb0x-Xtract0r
Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Powershell module for VMWare vSphere forensics

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

Selective protocol extractor from PCAPs or interfaces

Zeek support for Community ID flow hashing.

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Controlled reproduction of CVE-2017-0144 (EternalBlue) in an isolated AWS EC2 lab — exploit analysis, Wireshark traffic capture, and MITRE ATT&CK…

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…

The Multiplatform Linux Sandbox

A network sniffer that logs all DNS server replies for use in a passive DNS setup

TCP/IP packet demultiplexer. Download from:

Visualize network topologies and collect graph statistics based on pcap files

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

create cypher create statements for neo4j out of netstat files from multiple machines

A network packet forensics tool for SSH