
dfirtriage
Digital forensic acquisition tool for Windows based incident response.

Digital forensic acquisition tool for Windows based incident response.

Multi-layered malware scanner combining hash-based verification, behavioral analysis, and sandbox execution for threat detection, incident response,…

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Extract Windows credentials directly from VM memory snapshots and virtual disks

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A python script developed to process Windows memory images based on triage type.

A Windows kernel dump C++ parser library with Python 3 bindings.

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…