Lyc4on / EvtXHuntLinks
EvtXHunt is an Autopsy plugin that is able to analyze Windows EVTX logs against a library of SIGMA rules.
☆16Updated 3 years ago
Alternatives and similar repositories for EvtXHunt
Users that are interested in EvtXHunt are comparing it to the libraries listed below
Sorting:
- Linux Baseline and Forensic Triage Tool - BETA☆57Updated 3 years ago
- ☆20Updated 3 months ago
- A preconfigured Windows-based system designed for rapid forensic investigations in both Azure and AWS.☆38Updated last year
- unix_collector is a Live Response collection script for Incident Response on UNIX-like systems using native binaries. Supports AIX, Andro…☆38Updated 4 months ago
- Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or event…☆78Updated 4 years ago
- Thor Artifacts for Velociraptor☆17Updated last year
- Linux Evidence Acquisition Framework☆118Updated last year
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆31Updated 8 months ago
- Penguin OS Forensic (or Flight) Recorder☆41Updated 9 months ago
- Initial triage of Windows Event logs☆102Updated last year
- Quick ESXi Log Parser☆26Updated last month
- Various commands, tools, techniques that you can use to examine live Windows systems for signs of Compromise or for Threat Hunting.Can al…☆12Updated 3 years ago
- Contains Actual Events and Codes of Threat Groups, APTs, Research Groups☆19Updated 3 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆26Updated 2 weeks ago
- A repository for tracking events related to the MOVEit Transfer Cl0p Campaign☆71Updated 2 years ago
- ESXi Cyber Security Incident Response Script☆25Updated last year
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated 2 years ago
- All the useful tools interesting to be used☆23Updated 3 years ago
- Contains compiled binaries of Volatility☆35Updated 4 months ago
- A MITRE ATT&CK Lookup Tool☆45Updated last year
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆34Updated 3 months ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated last year
- A script to assist in processing forensic RAM captures for malware triage☆27Updated 4 years ago
- Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents☆49Updated last year
- Jupyter Notebooks for the Blue Team☆36Updated 8 months ago
- Forensic Artifact Collection Tool Matrix☆91Updated 11 months ago
- Chrome/Chromium Forensic Tool : Parses History, Visited Links, Downloaded Files and Cache☆18Updated last year
- ☆22Updated 2 years ago
- BlueBox Malware analysis Box and Cyber threat intelligence.☆43Updated 3 years ago
- ☆29Updated 9 months ago