
bulk_extractor
This is the development tree. Production downloads are at:
data-recoverydigital-forensicsdisk-forensics+9
1.4k

This is the development tree. Production downloads are at:

Malicious HTTP traffic explorer

Decodes PlugX traffic and encrypted/compressed artifacts

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

CVE-2017-0199 XLS --> HTA --> VBS --> STEGANOGRAPHY --> DBATLOADER/GULOADER STYLE MALWARE