Skip to content
View aaarghhh's full-sized avatar

Highlights

  • Pro

Block or report aaarghhh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

DFIR

26 repositories

Digging Deeper....

Go 3,786 597 Updated Mar 2, 2026

Project based on RegRipper, to extract add'l value/pivot points from TLN events file

Perl 89 10 Updated Feb 9, 2025

Browser forensics tool for Google Chrome (and other Chromium-based browsers)

Python 1,388 174 Updated Mar 1, 2026

research chrome stored databases - dumping all urls

Python 42 6 Updated Nov 11, 2017

Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifyin…

1,142 111 Updated Dec 19, 2025

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

PowerShell 489 73 Updated Nov 21, 2024

Tool and framework for securely reading untrusted USB mass storage devices.

Rust 368 33 Updated Feb 27, 2026

extract info from apk files

Go 86 12 Updated Feb 24, 2026

Frontend to explore the internals of a PDF document with Origami

Ruby 40 4 Updated Oct 7, 2017

Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL

Rust 64 8 Updated Sep 12, 2022

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Rust 1,658 122 Updated Jan 8, 2025

UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of U…

Shell 1,249 181 Updated Feb 25, 2026

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Rust 3,047 259 Updated Feb 24, 2026

A repository to share publicly available Velociraptor detection content

YARA 196 25 Updated Mar 1, 2026

Cobalt Strike - Malleable C2 Profiles. A collection of profiles used in different projects using Cobalt Strike https://www.cobaltstrike.com/.

868 159 Updated Oct 28, 2022

Tools and Techniques for Blue Team / Incident Response

3,943 599 Updated Mar 27, 2025

CTF styled Digital Forensics labs, as offered in FAST NUCES Karachi during Spring 2023.

PHP 331 80 Updated Apr 14, 2023

RDP Bitmap Cache parser

Python 632 95 Updated Jan 21, 2025

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

C++ 310 23 Updated Sep 3, 2023

all shell backdoor in the world

Hack 338 55 Updated Jan 9, 2024

Rust in-memory dumper

Rust 108 17 Updated Jul 26, 2023

Rapidly Search and Hunt through Windows Forensic Artefacts

Rust 3,460 297 Updated Mar 2, 2026

Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.

485 86 Updated Nov 22, 2024

Steganography & PNG - Hide information inside PNG images

Go 56 11 Updated Dec 5, 2021

Decrypt Signal encrypted backups outside the app

Go 719 71 Updated Oct 28, 2019