Queries to parse sysmon event log file with microsoft logparser
☆60Mar 31, 2015Updated 11 years ago
Alternatives and similar repositories for sysmon-queries
Users that are interested in sysmon-queries are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- UI for forensic filtering of filesystem mac times.☆15May 14, 2020Updated 6 years ago
- This is a framework written in EnScript to utilize the network capabilities of EnCase. The purpose is to allow for someone to build a qui…☆13Apr 22, 2015Updated 11 years ago
- MacOS incident Response Toolkit. Mostly written while stuck on a NJTransit train.☆20Feb 20, 2020Updated 6 years ago
- A Windows Event Processing Utility☆47Feb 21, 2018Updated 8 years ago
- PowerShell module for creating and managing Sysinternals Sysmon config files.☆213Mar 29, 2021Updated 5 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Reconstruct process trees from event logs☆148Aug 12, 2020Updated 6 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆41Jul 29, 2020Updated 6 years ago
- Small scripts and POCs related to digital forensics☆18Nov 1, 2022Updated 3 years ago
- The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted driv…☆345Jun 25, 2022Updated 4 years ago
- Maps process creation logged by Sysmon uses Google Org Chart API☆23Mar 5, 2016Updated 10 years ago
- Create an incident response triage toolkit for use with Windows or Linux.☆18Jun 14, 2020Updated 6 years ago
- A threat hunting / data analysis environment based on Python, Pandas, PySpark and Jupyter Notebook.☆250Jul 19, 2021Updated 5 years ago
- Parser for Windows PowerShell script block logs☆101Aug 4, 2024Updated 2 years ago
- cuckoo sandbox patches and scripts☆14Jan 30, 2014Updated 12 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Web interface for the Volatility Memory Forensics Framework☆258Nov 21, 2017Updated 8 years ago
- Registry Miner☆14Apr 10, 2018Updated 8 years ago
- Some IR notes☆72Jul 23, 2016Updated 10 years ago
- Server for receiving autorun data from the clients☆13Sep 26, 2017Updated 8 years ago
- Triage automation for suspect URLs☆13Jul 23, 2019Updated 7 years ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆942Dec 12, 2023Updated 2 years ago
- An NTFS journal parser☆80Mar 3, 2016Updated 10 years ago
- Python tools for IOC (Indicator of Compromise) handling☆96Nov 25, 2021Updated 4 years ago
- Fast incident overview☆41Feb 11, 2017Updated 9 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Query and report user logons relations from MS Windows Security Events☆241Aug 9, 2018Updated 8 years ago
- Parallel ssdeep clustering kit☆21Dec 24, 2017Updated 8 years ago
- VolDiff: Malware Memory Footprint Analysis based on Volatility☆195Sep 12, 2017Updated 8 years ago
- Open Development projects for TekDefense☆78Oct 5, 2016Updated 9 years ago
- ☆435May 3, 2023Updated 3 years ago
- Unpack MIME attachments from a file and check them against virustotal.com☆44Mar 11, 2016Updated 10 years ago
- Python unbup script for McAfee .bup files (with some additional fun features). This script is fully implemented in python it's not just a…☆37Apr 24, 2018Updated 8 years ago
- Automating forensic data extraction, reduction, and overall triage of cold disk and memory images.☆21Mar 12, 2019Updated 7 years ago
- ☆351Mar 19, 2021Updated 5 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- An Ubuntu 16.04 build containing Suricata, PulledPork, Bro, and Splunk☆22Jul 10, 2018Updated 8 years ago
- A Python script for performing analysis of the output from Microsoft's Sysinternals Autoruns.☆15Feb 5, 2012Updated 14 years ago
- AuditParser☆61Aug 28, 2013Updated 12 years ago
- InvestigationPlaybookSpec☆70Sep 26, 2017Updated 8 years ago
- Web App for Volatility framework☆387Jan 13, 2026Updated 7 months ago
- **BETA** A simple buildscript for network security monitoring on RHEL/CentOS☆31Apr 4, 2017Updated 9 years ago
- Yara is awesome, but sometimes you need to manipulate the data streams you're scanning in different ways.☆97Oct 21, 2014Updated 11 years ago