ForensicRS / forensic-rs
Forensic framework to build tools that can be reused in multiple projects without changing anything
☆23Updated 9 months ago
Alternatives and similar repositories for forensic-rs:
Users that are interested in forensic-rs are comparing it to the libraries listed below
- Scanner for certain IoCs☆11Updated 9 months ago
- A document tagging library☆29Updated last year
- lnk_parser is a full rust implementation to parse windows LNK files☆16Updated 2 weeks ago
- Windows file metadata / forensic tool.☆16Updated 4 months ago
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆42Updated last year
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Updated 2 years ago
- ☆21Updated 3 months ago
- Vovk is framework of tools that include a WinDbg extension that generates in-depth YARA rules for malware.☆22Updated 4 months ago
- A proof-of-concept re-assembler for reverse VNC traffic.☆25Updated last year
- A Windows registry file parser written in Rust☆36Updated last year
- Python wrappers for mal_unpack☆35Updated last year
- Collection of my own detection rules☆14Updated 10 months ago
- Symantec EDR Internals☆25Updated 3 years ago
- ☆14Updated last month
- Indicators of Normality☆12Updated 2 years ago
- These FLARE-VM configuration files are designed to be help setup a purpose-built installation, remove unnecessary packages to help stream…☆13Updated 9 months ago
- General malware analysis stuff☆36Updated 4 months ago
- Provides a multi-platform Graphical User Interface for hashlookup☆12Updated 6 months ago
- Manage Your Large Team of Consultants☆11Updated this week
- A collection of my yara rules☆35Updated last year
- 🚧 Currently transfering TLP:CLEAR rules from TLP:AMBER repository...☆22Updated 9 months ago
- Exfiltrate data over audio output from remote desktop sessions - Covert channel PoC☆32Updated last month
- Can you pay the ransom in your country?☆13Updated last year
- Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.☆12Updated last year
- This repository contains an IDA processor for loading and disassembling compiled yara rules.☆27Updated 2 weeks ago
- ☆14Updated last year
- MalStatWare automates malware analysis with Python. Extract key details like file size, type, hash, path, and digital signature. It analy…☆29Updated 8 months ago
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆10Updated 2 weeks ago
- SRE - Dissecting Malware for Static Analysis & the Complete Command-line Tool☆51Updated 3 weeks ago
- Parser for Windows PowerShell script block logs☆13Updated 2 weeks ago