
Baskerville
Selective protocol extractor from PCAPs or interfaces

Selective protocol extractor from PCAPs or interfaces

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

OpenFPC, Open Source Full Packet Capture

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Visualize network topologies and collect graph statistics based on pcap files

A Zeek Wireguard protocol analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement…

Powershell module for VMWare vSphere forensics

All-in-One malware analysis tool.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…