DFIR-ORC / dfir-orc-config
Configurations for DFIR ORC
☆26Updated 10 months ago
Alternatives and similar repositories for dfir-orc-config:
Users that are interested in dfir-orc-config are comparing it to the libraries listed below
- Extract BITS jobs from QMGR queue and store them as CSV records☆75Updated last week
- ☆33Updated 4 months ago
- A Splunk Technology Add-on to forward filtered ETW events.☆30Updated 4 years ago
- Steezy - Ghetto Yara Generation☆15Updated last year
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆39Updated 2 years ago
- evtx2json extracts events of interest from event logs, dedups them, and exports them to json.