Open source · APT research
The work behind the retainer.
Six open-source DFIR tools, published research on state-sponsored actors, and the forums where we present it. Free to use, free to read, no gate.
Open-source tooling
Built by responders, for respondersM365 forensics
Aug 2025MAES
The M365 Analyzer & Extractor Suite — extract, analyze and preserve evidence from Microsoft 365 tenants with SHA-256 chain of custody.
Read the release → about MAESFortinet forensics
Aug 2025Forti-DFIR
Open-source framework giving security teams the tooling they need for forensic investigations and incident response in Fortinet environments.
Read the release → about Forti-DFIRPrevention
Jul 2025RansomProtect
Detects and blocks ransomware and wipers early in the infection chain, where built-in OS defenses fall short.
Read the release → about RansomProtectCloud posture
Aug 2025FlareInspect
CLI assessment framework for evaluating and monitoring an organization’s Cloudflare security posture.
Read the release → about FlareInspectEvidence capture
Aug 2025DO Audit Log Scraper
Chrome/Chromium extension enabling forensic-grade audit log extraction. Now at v2.0.
Read the release → about DO Audit Log ScraperCompliance
Aug 2025Tikun13 Checker
Browser-based open-source checker helping Israeli organizations implement the requirements of Amendment 13 to the Privacy Protection Law.
Read the release → about Tikun13 CheckerThreat research
Campaigns we tracked, actors we named, and intrusions we took apart — written up in full.
Where we present it
2025
GISEC Global
Israeli Pavilion, Dubai — preview of our next-generation DFIR platform.
2025
IMPROVATE CISO Summit
Connecting with Israel’s leading cybersecurity executives.
2024
HackExpo
Breach at the frontline — responding to fintech exploits under live pressure.
2024
GPEC
Showcasing APT research among 471 exhibitors from 32 countries.
2024
MIRROR Forum with INCD
Third forum of 15 Israeli IR companies, convened by the national cyber directorate.