Memory Forensics Toolkit
Advanced memory analysis framework for Windows and Linux systems. Includes custom plugins for rootkit detection, process injection analysis, and ransomware artifact extraction.
CloudTrail Analyzer
Real-time AWS CloudTrail log analysis tool for detecting suspicious activities in cloud environments. Implements ML-based anomaly detection and automated incident triage.
Malware Sandbox Automation
Automated malware analysis pipeline with dynamic and static analysis capabilities. Generates comprehensive reports including IoCs, behavioral analysis, and MITRE ATT&CK mapping.
Network Forensics Platform
Distributed network forensics platform for capturing and analyzing network traffic at scale. Features protocol dissection, pattern matching, and automated threat hunting.
Ransomware Detection Engine
Machine learning-based ransomware detection system that monitors file system activities and network behaviors to identify encryption attempts in real-time.
DFIR Automation Scripts
Collection of PowerShell and Python scripts for automating common digital forensics and incident response tasks. Includes triage, evidence collection, and timeline analysis.
These projects are open source and available for contribution. Feel free to fork, submit PRs, or reach out for collaboration opportunities.