
z9
Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain


Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

gundog - guided hunting in Microsoft Defender

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

Run on your ManageEngine server