


An OSINT investigation case mapping tool for organizing entities, relationships, evidence, and intelligence.

Reverse engineering analysis of PureRAT RAT abusing msbuild.exe, extracting C2 infrastructure, .NET evasion APIs, file system manipulation, and…

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Extensible MacOS system telemetry generator.

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

This is the development tree. Production downloads are at:

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Strelka Web UI for File Submission and Analysis

Tools and Techniques for Blue Team / Incident Response

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

Real-time, container-based file scanning at enterprise scale

CVE-2026-54984 / ZDI-26-543: Windows ICC file parsing out-of-bounds write (CWE-122, CVSS 7.8)

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

This package extends the Intel package to log more fields

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…