Skip to content
View Qazeer's full-sized avatar

Block or report Qazeer

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (EXT4, XFS) journals (not systemd-journald), generates timelines, and detects suspicious activities.

Python 64 6 Updated Apr 4, 2025

USN Journal full path builder

Python 60 5 Updated Sep 16, 2024

Local & remote Windows DLL Proxying

Python 164 24 Updated Jun 17, 2024

Digital Forensics Investigation Platform

JavaScript 826 114 Updated Oct 12, 2024

MemProcFS

C 3,578 480 Updated May 20, 2025

Automated YARA Rule Standardization and Quality Assurance Tool

Python 221 27 Updated May 18, 2025

Yet Another Memory Analyzer for malware detection

C++ 183 95 Updated Apr 8, 2025

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

PowerShell 630 91 Updated May 19, 2025

HVNC for Cobalt Strike

C 1,223 186 Updated Dec 7, 2023

AADInternals PowerShell module for administering Azure AD and Office 365

PowerShell 1,425 230 Updated Apr 24, 2025

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Python 1,431 180 Updated Jul 31, 2024

Public script from SANS FOR509 Enterprise Cloud Incident Response

Python 200 41 Updated Sep 13, 2024

Configuration files for the SOF-ELK VM

Shell 1,588 293 Updated Apr 1, 2025

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

C# 526 65 Updated Sep 18, 2022

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

Go 1,443 186 Updated Aug 18, 2023

Universal Winlogbeat configuration

33 5 Updated Mar 18, 2022

Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...

1,076 182 Updated Sep 4, 2024

Canarytokens helps track activity and actions on your network.

HTML 1,842 266 Updated May 22, 2025

E-Mail Header Analyzer

HTML 672 168 Updated Apr 11, 2023

Elastic Security detection content for Endpoint

YARA 1,198 136 Updated May 8, 2025

A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.

Python 520 74 Updated Aug 1, 2022

Detect and respond to Cobalt Strike beacons using ETW.

C# 498 49 Updated Jul 15, 2022

An advanced tool for working with access tokens and Windows security policy.

Pascal 611 66 Updated Jul 20, 2024

A tool to kill antimalware protected processes

C 1,447 244 Updated Jun 19, 2021

Dumping DPAPI credz remotely

Python 1,123 131 Updated Mar 24, 2025
Next