DFIR & TI & REM
consult-org-roam. A bunch of convenience functions for operating org-roam with the help of consult
161spamtrap-system. Collection of tools to build and run a distributed spamtrap system, consisting of IMAP and SMTP collectors and a backend that extracts attachments, potentially analyzes malware and reports results to MISP or ES.
14vmi-gui-reconstruction. Proof-of-concept code to reconstruct the GUI of a Xen guest running Windows
14ansible-forensic-workstation. An Ansible playbook to create a basic Debian-based workstation for forensic tasks.
8org-roam-ui. A graphical frontend for exploring your org-roam Zettelkasten
5org-roam-desktop. A dead-simple desktop facility for org-roam
5xmpp-mitm. Python utility that decrypts TLS encrypted XMPP traffic by acting as an active MITM and looking for STARTTLS requests
5onion-domain-harvester. Small python tool to harvest onion domains and store them in a SQLite DB. Onion domains are scraped from the hiddenwiki and several clear web webpages, which list onion-domains.
4ansible-drakvuf. Ansible role to install the black-box binary analysis DRAKVUF
3hashlab. Generates lists of hashes of known benign and common files from Vagrant boxes in an automated manner for the use of whitelisting in DFIR workflows.
2libja3. WIP! - C-Library to compute JA3 TLS fingerprints
2ansible-cuckoo-virtualbox. Ansible role to deploy a Cuckoo sandbox host, which uses VirtualBox VMs as machinery
2ufed-geo2x. This is a simple utility to extract geolocation data from a .xml-report of Cellebrite's UFED Physical Analyzer.
2mailworm. Utility to parse a bunch of e-mails in .msg/.eml-format, to extract the most relevant information (header fields, attachments and their metadata), to enrich those information and store it in a .sqlite file
2dfir-smb-share. A Docker-based SMB Share for DFIR work, which offers strong integrity protection by utilizing a trusted timestamping service
1toolkit-obfuscator. Collection of simple scripts to modifiy a live response toolkit
1grus-ghidra-scripts. Just a collection of my Ghidra/scripts to aid malware reversing
1stream-to-s3. Stream data from stdin into an S3-bucket
1raw-converter. Implementation of a raw processing pipeline to process .cr2-Files. Additionally flat stitching of raw-files by preserving their raw nature is conducted. Bachelor's project from 2014
1docker-snort3. Lua
1