
ADFT
Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Apache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon…

🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781

VirusTotal Wanna Be - Now with 100% more Hipster

CVE-2021-44228 DFIR Notes

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

My Citrix ADC NetScaler CVE-2019-19781 Vulnerability DFIR notes.

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework