
MrHandler
SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Multi-layered malware scanner combining hash-based verification, behavioral analysis, and sandbox execution for threat detection, incident response,…

Incident Response collection and processing scripts with automated reporting scripts

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Cortex: a Powerful Observable Analysis and Active Response Engine

Detection-as-code platform that automates cloud security incident response by correlating artifacts, analyzing IOCs, and orchestrating…


A Windows kernel dump C++ parser library with Python 3 bindings.

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Python-based scanner for CVE-2025-55182 indicators of compromise. Checks filesystem paths, processes, systemd services, cron persistence, and…

Easy-to-use live forensics toolbox for Linux endpoints

Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

Volatility plugin for extracts configuration data of known malware

Automagically extract forensic timeline from volatile memory dump