Category: Forensics

Deobfuscate Log4Shell payloads

Ox4Shell: Deobfuscate Log4Shell payloads

Ox4Shell Deobfuscate Log4Shell payloads with ease. Since the release of the Log4Shell vulnerability (CVE-2021-44228), many tools were created to obfuscate Log4Shell payloads, making the lives of security engineers a nightmare. This tool intends to...

command-line toolkit

dismember: scan the memory of all processes

Dismember Dismember is a command-line toolkit for Linux that can be used to scan the memory of all processes (or particular ones) for common secrets and custom regular expressions, among other things. It will...

Shodan Monitoring

shomon: Shodan Monitoring integration for TheHive

shomon ShoMon is a Shodan alert feeder for TheHive written in GoLang. With version 2.0, it is more powerful than ever! Functionalities Can be used as Webhook OR Stream listener Webhook listener opens a...

Linux Audit logs

laurel v0.5.3 releases: Transform Linux Audit logs for SIEM usage

Linux Audit – Usable, Robust, Easy Logging LAUREL is an event post-processing plugin for auditd(8) to improve its usability in modern security monitoring setups. Logs produced by the Linux Audit subsystem and auditd(8) contain information that can...

ETW Tracing

Sealighter: Easy ETW Tracing for Security Research

Sealighter – Easy ETW Tracing for Security Research Sealighter leverages the feature-rich Krabs ETW Library to enable detailed filtering and triage of ETW and WPP Providers and Events. You can subscribe and filter multiple providers, including...

identify beacons

Hunt-Sleeping-Beacons: identify beacons

Hunt-Sleeping-Beacons The idea of this project is to identify beacons which are unpacked at runtime or running in the context of another process. To do so, I make use of the observation that beacons...

network monitoring tool

goreplay: open-source network monitoring tool

goreplay GoReplay is an open-source network monitoring tool which can record your live traffic and use it for shadowing, load testing, monitoring, and detailed analysis. As your application grows, the effort required to test...