4n6ist / usn_analytics
It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.
☆23Updated 6 years ago
Alternatives and similar repositories for usn_analytics:
Users that are interested in usn_analytics are comparing it to the libraries listed below
- Handy scripts to speed up malware analysis☆35Updated last year
- Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research☆53Updated 6 years ago
- Network detector for Winnti malware☆20Updated 6 years ago
- Trace ScriptBlock execution for powershell v2☆39Updated 5 years ago
- Generate a Yara rule to find base64-encoded files containg a specific keyword☆41Updated 6 years ago
- Binary commandline executable to parse ETL files☆67Updated 6 years ago
- A Maltego transform for VirusTotal Submitter Information☆32Updated 5 years ago
- ConventionEngine - A Yara Rulepack for PDB Path Hunting☆37Updated last year
- Extract compressed memory pages from page-aligned data☆42Updated 6 years ago
- Event Log Analysis Tools☆29Updated 8 years ago
- Volatility Framework plugin to detect various types of hooks as performed by banking Trojans☆40Updated 6 years ago
- API functions for Malware Research☆35Updated 5 years ago
- Shows command lines used by latest instances analyzed on Hybrid-Analysis☆43Updated 6 years ago
- Parses the WMI object database....looking for persistence☆31Updated 5 years ago
- Modified edition of cuckoomon☆48Updated 6 years ago
- radare2 script to help on COM objects reverse engineering☆11Updated 7 years ago
- A Maltego transform for VirusTotal vHash☆31Updated 5 years ago
- Telsy CTI Research Team☆57Updated 4 years ago
- Script to parse Process Monitor XML log file, and give you a summary report.☆23Updated 8 years ago
- TA505 unpacker Python 2.7☆47Updated 4 years ago
- A python script that can be used to scan data within in an IDB using Yara.☆22Updated 6 years ago
- Capture-Py is a malware analysis tool that makes a copy of any files deleted or modified in a given directory and sub-directories. It was…☆23Updated 7 years ago
- ☆47Updated 5 years ago
- Steezy - Ghetto Yara Generation☆15Updated last year
- a modified version base on Tracecorn☆20Updated 5 years ago
- A collection of threat intelligence data such as IOC, Yara and Snort/Suricata Rules etc.☆10Updated 5 years ago
- Scans through registry hives outputting entropy values for key/values, dumps binary contents to files...we are looking for those "fileles…☆11Updated 6 years ago
- ☆36Updated 5 years ago
- CAPE monitor DLLs☆39Updated 5 years ago