Skip to content
View Qazeer's full-sized avatar

Block or report Qazeer

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), generates timelines, and detects suspicious activities.

Python 103 9 Updated Jan 13, 2026

USN Journal full path builder

Python 65 6 Updated Sep 16, 2024

Local & remote Windows DLL Proxying

Python 170 23 Updated Jun 17, 2024

Digital Forensics Investigation Platform

JavaScript 872 120 Updated Oct 12, 2024

MemProcFS

C 4,007 510 Updated Feb 7, 2026

Automated YARA Rule Standardization and Quality Assurance Tool

Python 284 35 Updated Feb 15, 2026

Yet Another Memory Analyzer for malware detection

C++ 203 100 Updated Apr 8, 2025

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

PowerShell 768 112 Updated Jan 15, 2026

HVNC for Cobalt Strike

C 1,296 199 Updated Dec 7, 2023

AADInternals PowerShell module for administering Azure AD and Office 365

PowerShell 1,587 249 Updated Sep 30, 2025

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Python 1,585 199 Updated Jul 31, 2024

Public script from SANS FOR509 Enterprise Cloud Incident Response

Python 219 43 Updated Oct 26, 2025

Configuration files for the SOF-ELK VM

Ruby 1,714 299 Updated Jan 21, 2026

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

C# 538 65 Updated Sep 18, 2022

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

Go 1,469 197 Updated Aug 18, 2023

Universal Winlogbeat configuration

33 5 Updated Mar 18, 2022

Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...

1,088 181 Updated Nov 8, 2025

Canarytokens helps track activity and actions on your network.

HTML 2,021 276 Updated Feb 12, 2026

E-Mail Header Analyzer

HTML 695 168 Updated Apr 11, 2023

Elastic Security detection content for Endpoint

YARA 1,374 152 Updated Feb 12, 2026

A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.

Python 536 76 Updated Aug 1, 2022

Detect and respond to Cobalt Strike beacons using ETW.

C# 520 49 Updated Jul 15, 2022

An advanced tool for working with access tokens and Windows security policy.

Pascal 634 68 Updated Dec 20, 2025

A tool to kill antimalware protected processes

C 1,504 250 Updated Jun 19, 2021
Next