
keepass-exfil-forensics
Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Lua plugin to extract data from Wireshark and convert it into MISP format

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…