
easy_triage
Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)

Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Android Logs Events And Protobuf Parser

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

A Windows kernel dump C++ parser library with Python 3 bindings.

Cortex: a Powerful Observable Analysis and Active Response Engine

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.

Detecting vulnerabilities like CVE-2024-0762, particularly in UEFI firmware, is quite challenging due to the low-level nature

Python-based scanner for CVE-2025-55182 indicators of compromise. Checks filesystem paths, processes, systemd services, cron persistence, and…

An event-driven network monitoring platform that performs live packet capture (Npcap), low-latency traffic analytics, and unsupervised threat…

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

Detection Script for MongoBleed Exploitation

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response