0xHasanM / Autopsy-Registry-Explorer
Autopsy Module to analyze Registry Hives
☆14Updated 2 years ago
Alternatives and similar repositories for Autopsy-Registry-Explorer:
Users that are interested in Autopsy-Registry-Explorer are comparing it to the libraries listed below
- Hash collisions and their exploitations☆9Updated 2 years ago
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆22Updated 2 years ago
- Parser for Sdba memory pool tags☆17Updated 3 years ago
- Notepad++ Syntax Highlighting for Languages Used by Cyber Security Professionals☆14Updated 4 years ago
- Help deobfuscate VBScript☆15Updated 2 years ago
- Collection of tips, tools, arsenal and techniques I've learned during RE and other CyberSecStuff☆54Updated 8 months ago
- A set of tools for collecting forensic information☆26Updated 4 years ago
- Data from analysis of the custom sample from the chapter "Practical Analysis and Test"☆12Updated 4 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆15Updated 11 months ago
- Static Decryptor for IcedID Malware☆18Updated 2 years ago
- ☆22Updated 4 years ago
- ☆18Updated 3 weeks ago
- This repo contains miscellaneous tools to aid in your malware analysis.☆12Updated 3 years ago
- Parser for Windows PowerShell script block logs☆13Updated last month
- Speaking materials from conferences I've given☆9Updated 2 years ago
- ☆21Updated 3 months ago
- A PowerShell script to prevent Sysmon from writing its events☆14Updated 4 years ago
- ☆12Updated 4 years ago
- Collection of my own detection rules☆14Updated 11 months ago
- ☆24Updated 5 years ago
- Proof of concept - Covert Channel using Windows Filtering Platform (C#)☆21Updated 3 years ago
- A collection of threat intelligence data such as IOC, Yara and Snort/Suricata Rules etc.☆10Updated 5 years ago
- A powershell parser for https://github.com/ufrisk/MemProcFS☆44Updated 3 years ago
- ☆12Updated 3 years ago
- Carve files for MFT entries (eg. blkls output or memory dumps). Recovers filenames (long & short), timestamps ($STD & $FN) and data if re…☆21Updated 5 years ago
- Registry hive parsing the async way☆20Updated 4 months ago
- Links to malware-related YARA rules☆14Updated 2 years ago
- ☆22Updated last year
- Tricard - Malware Sandbox Fingerprinting☆19Updated last year
- Yara rules☆20Updated last year