
OpenFPC
OpenFPC, Open Source Full Packet Capture

OpenFPC, Open Source Full Packet Capture

DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement…

Powershell module for VMWare vSphere forensics

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

All-in-One malware analysis tool.

Visualize network topologies and collect graph statistics based on pcap files

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…

Selective protocol extractor from PCAPs or interfaces

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

LetsDefend SOC lab investigating CVE-2024-49138 exploitation and related malicious activity.

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)