IONSEC

Open source · APT research

The work behind the retainer.

6 open-source DFIR tools, published research on state-sponsored actors, and the forums where we present it. Free to use, free to read, no gate.

What chain of custody means

Every artefact our tooling touches is acquired read-only, digested to a SHA-256 hash, and sealed against that hash. It is the difference between evidence that holds up and a folder of files someone copied — and it is why the tools are open source: you can check the claim yourself.
  • Artefact acquired
  • SHA-256 digest
  • Sealed

Open-source tooling

Built by responders, for responders

M365 forensics

Aug 2025

MAES

The M365 Analyzer & Extractor Suite — extract, analyze and preserve evidence from Microsoft 365 tenants with SHA-256 chain of custody.

Read the release →<span class="sr-only"> about MAES</span>

Fortinet forensics

Aug 2025

Forti-DFIR

Open-source framework giving security teams the tooling they need for forensic investigations and incident response in Fortinet environments.

Read the release →<span class="sr-only"> about Forti-DFIR</span>

Prevention

Jul 2025

RansomProtect

Detects and blocks ransomware and wipers early in the infection chain, where built-in OS defenses fall short.

Read the release →<span class="sr-only"> about RansomProtect</span>

Cloud posture

Aug 2025

FlareInspect

CLI assessment framework for evaluating and monitoring an organization’s Cloudflare security posture.

Read the release →<span class="sr-only"> about FlareInspect</span>

Evidence capture

Aug 2025

DO Audit Log Scraper

Chrome/Chromium extension enabling forensic-grade audit log extraction. Now at v2.0.

Read the release →<span class="sr-only"> about DO Audit Log Scraper</span>

Compliance

Aug 2025

Tikun13 Checker

Browser-based open-source checker helping Israeli organizations implement the requirements of Amendment 13 to the Privacy Protection Law.

Read the release →<span class="sr-only"> about Tikun13 Checker</span>

GitHub

trace

TRACE — AI and compute forensic evidence collector by IONSEC. Python CLI and Go binary with near-identical capabilities: 27 collectors, 47 shadow-AI tool detections, 103-rule secret detection, conversation forensics, MITRE ATLAS/ATT&CK, kill chain, risk scoring, HTML/JSON/STIX reports, Velociraptor artifacts.

View on GitHub →<span class="sr-only">: trace</span>

GitHub

7★

OpenClaw-Threat-Intel

Multi-Source Skill for Threat Intelligence Enrichment for Incident Response

View on GitHub →<span class="sr-only">: OpenClaw-Threat-Intel</span>

GitHub

3★

remnux-malware-triage

Triage-first malware analysis workflow for REMnux (OpenClaw skill)

View on GitHub →<span class="sr-only">: remnux-malware-triage</span>

GitHub

ESXiTri

ESXi Cyber Security Incident Response Script

View on GitHub →<span class="sr-only">: ESXiTri</span>

GitHub

4★

web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

View on GitHub →<span class="sr-only">: web-check</span>

Threat research

Campaigns we tracked, actors we named, and intrusions we took apart — written up in full.

ToolsIONSEC TRACE: Leave No Model Untraced — Open-Source Forensics for the AI HarnessIONSEC TRACE is an open-source, forensically sound collector and analyzer for AI harness evidence — now shipping a Python CLI and a Go binary with near-identical capabilities, a 103-rule secret detector, and conversation secret hunting.Aug 2026 · 14 minArticleXSS2Shell: One Failed Login to PHP on the ServerCVE-2026-64638 is a reflected XSS on the WordPress login page — the finding most teams close as medium. Six gadgets sit between it and a PHP shell, and every one of them was already in core. Here is the chain, the log signatures, and what to harden after you patch.Aug 2026 · 14 minArticleXSS2Shell: מניסיון התחברות כושל אחד ועד PHP על השרתCVE-2026-64638 היא חולשת XSS מוחזר בעמוד ההתחברות של וורדפרס — בדיוק הממצא שרוב הצוותים סוגרים כבינוני. בין החולשה הזו לבין הרצת PHP על השרת עומדים שישה שלבים נוספים, וכולם כבר היו בליבת המערכת. הנה השרשרת המלאה, חתימות הזיהוי בלוגים, וההקשחה שצריך לעשות אחרי העדכון.Aug 2026 · 15 minArticleThe Machine Has No Disk: Forensic Readiness for AI Agent RuntimesForensic readiness for AI agent runtimes — Cloudflare Computer, NVIDIA OpenShell, and the collapse of the endpoint as an evidence source.Aug 2026 · 30 minArticleCoercion to krbtgt: NTLM Relay and ADCS ESC8 in 2026A full ESC8 walkthrough against a lab domain, then the forensic reconstruction — why the certificate serial, not the source IP, is the artifact that ties the whole chain together.Jul 2026 · 15 minBlogThe 60-Minute Site: Phishing That Deletes Its Own EvidenceCloudflare Drop publishes a site on a trusted workers.dev address with no account, then deletes it after an hour. That one-hour fuse burns your forensic evidence with it.Jul 2026 · 6 minCase StudyWhen Research Meets RealityHow Threat-Actor Campaigns Cast a Shadow on Legitimate npm Binaries (and What IONSEC IR Sees in the wild)Jul 2025 · 8 minCase StudyHow a Weaponized Zoom Installer Opened the Door for BlueNoroffIONSEC investigates a BlueNoroff intrusion that began with a weaponized Zoom installer, combining deepfakes, social engineering and evasive scripting.Jul 2025 · 8 minCase StudyIranian Threat Actor Hijacks DNSקבוצת התקיפה האיראנית פתח אלקודס פרצה לרשם דומיינים ישראלי ושינתה רשומות DNS ו-MX של יותר מ-1,000 דומיינים, והפנתה אותם לשרת זדוני ולדף תעמולה.Jul 2025 · 9 minArticleWhy Malware Analysis Training is Vital: Lessons from Real-World Cyber AttacksPicture this: airport metal detectors efficiently catch large, obvious weapons, but small components slip through unnoticed. Once inside, attackers assemble them into a complete weapon.Dec 2024 · 1 minBlogReverse Engineering GodPotato (MSASCui.exe)Privilege escalation is a critical technique employed by attackers to gain unauthorized access to higher system privileges, often leading to significant security breaches.Nov 2024 · 4 minBlogClearing the Mist: Unveiling Fog RansomwareA full analysis of the Fog Ransomware Group: the malware it deploys, the TTPs it relies on to infiltrate high-tech firms, and how defenders can disrupt it.Aug 2024 · 5 minBlogSovaTeam - New State-Sponsored APTHow IONSEC and White-Hat traced the Sova Team threat actor through a ransom note to uncover a state-sponsored APT operating past strict security controls.Mar 2024 · 8 minBlogסקירה מודיעינית 2024 #OpIsraelIONSEC הינה חברת בוטיק לשירותי אבטחת מידע ותגובה לאירועי סייבר (24/7) העוסקת במחקר ותגובה לאיומים מתקדמים ומספקת פתרונות אבטחה מותאמים אישית לחברות ברחבי העולם.Mar 2024 · 10 min