Open source · APT research
The work behind the retainer.
6 open-source DFIR tools, published research on state-sponsored actors, and the forums where we present it. Free to use, free to read, no gate.
What chain of custody means
- Artefact acquired
- SHA-256 digest
- Sealed
Open-source tooling
Built by responders, for respondersM365 forensics
Aug 2025MAES
The M365 Analyzer & Extractor Suite — extract, analyze and preserve evidence from Microsoft 365 tenants with SHA-256 chain of custody.
Read the release →<span class="sr-only"> about MAES</span>Fortinet forensics
Aug 2025Forti-DFIR
Open-source framework giving security teams the tooling they need for forensic investigations and incident response in Fortinet environments.
Read the release →<span class="sr-only"> about Forti-DFIR</span>Prevention
Jul 2025RansomProtect
Detects and blocks ransomware and wipers early in the infection chain, where built-in OS defenses fall short.
Read the release →<span class="sr-only"> about RansomProtect</span>Cloud posture
Aug 2025FlareInspect
CLI assessment framework for evaluating and monitoring an organization’s Cloudflare security posture.
Read the release →<span class="sr-only"> about FlareInspect</span>Evidence capture
Aug 2025DO Audit Log Scraper
Chrome/Chromium extension enabling forensic-grade audit log extraction. Now at v2.0.
Read the release →<span class="sr-only"> about DO Audit Log Scraper</span>Compliance
Aug 2025Tikun13 Checker
Browser-based open-source checker helping Israeli organizations implement the requirements of Amendment 13 to the Privacy Protection Law.
Read the release →<span class="sr-only"> about Tikun13 Checker</span>GitHub
trace
TRACE — AI and compute forensic evidence collector by IONSEC. Python CLI and Go binary with near-identical capabilities: 27 collectors, 47 shadow-AI tool detections, 103-rule secret detection, conversation forensics, MITRE ATLAS/ATT&CK, kill chain, risk scoring, HTML/JSON/STIX reports, Velociraptor artifacts.
View on GitHub →<span class="sr-only">: trace</span>GitHub
7★OpenClaw-Threat-Intel
Multi-Source Skill for Threat Intelligence Enrichment for Incident Response
View on GitHub →<span class="sr-only">: OpenClaw-Threat-Intel</span>GitHub
3★remnux-malware-triage
Triage-first malware analysis workflow for REMnux (OpenClaw skill)
View on GitHub →<span class="sr-only">: remnux-malware-triage</span>GitHub
ESXiTri
ESXi Cyber Security Incident Response Script
View on GitHub →<span class="sr-only">: ESXiTri</span>GitHub
4★web-check
🕵️♂️ All-in-one OSINT tool for analysing any website
View on GitHub →<span class="sr-only">: web-check</span>Threat research
Campaigns we tracked, actors we named, and intrusions we took apart — written up in full.
Where we present it
2025
GISEC Global 2025
Israeli Pavilion, Dubai — preview of our next-generation DFIR platform.
2025
IMPROVATE CISO Summit
Connecting with Israel’s leading cybersecurity executives.
2024
HackExpo 2024
Breach at the frontline — responding to fintech exploits under live pressure.
2024
GPEC 2024
Showcasing APT research among 471 exhibitors from 32 countries.
2024
3rd MIRROR Forum with the Israel National Cyber Directorate
Third forum of 15 Israeli IR companies, convened by the national cyber directorate.
2024
Czech delegation wiper malware briefing
Hosted a Czech delegation in Israel to present our wiper malware research, including the campaign we track as Operation HANDALA.