
DFIR-Companion
DFIR forensics companion server + capture extension

DFIR forensics companion server + capture extension

Zero-dependency, sub-second Windows live digital forensics & incident response (DFIR) triage engine for USB responders.

LetsDefend SOC lab investigating CVE-2024-49138 and related malicious activity.

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

Provides packet processing capabilities for Go

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

Powershell module for VMWare vSphere forensics

Writeup for the DEF CON 30 badge challenge

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

A list of cyber-chef recipes and curated links

You didn't think I'd go and leave the blue team out, right?

Wireshark RDP resources

Malware samples, analysis exercises and other interesting resources.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.