MarkBaggett / srum-dump
A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.
☆608Updated 3 months ago
Alternatives and similar repositories for srum-dump:
Users that are interested in srum-dump are comparing it to the libraries listed below
- CyLR - Live Response Collection Tool☆664Updated 2 years ago
- Tools for hunting for threats.☆579Updated 4 months ago
- A Powershell incident response framework☆1,588Updated 2 years ago
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆691Updated last week
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆912Updated last year
- Tool Analysis Result Sheet☆347Updated 7 years ago
- Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into …☆794Updated last year
- Online hash checker for Virustotal and other services☆822Updated 9 months ago
- Beacon Kibana Executable Report. Aggregates Sysmon Network Events With Elasticsearch and Kibana☆292Updated 5 months ago
- PowerShell Obfuscation Detection Framework☆730Updated last year
- Get all my software☆149Updated last month
- This is a set of tools for doing forensics analysis on Microsoft ESE databases.☆124Updated 3 years ago
- TrustedSec Sysinternals Sysmon Community Guide☆1,180Updated 9 months ago
- ☆297Updated 4 years ago
- The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifa…☆582Updated 3 months ago
- RegRipper3.0☆579Updated 2 months ago
- Investigate suspicious activity by visualizing Sysmon's event log☆419Updated last year
- PowerForensics provides an all in one platform for live disk forensic analysis☆1,393Updated last year
- A collection of red team and adversary emulation resources developed and released by MITRE.☆498Updated 3 years ago
- Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux☆498Updated 2 years ago
- The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted driv…☆336Updated 2 years ago
- Misc Threat Hunting Resources☆373Updated 2 years ago
- C# based evtx parser with lots of extras☆290Updated 3 weeks ago
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆604Updated 8 months ago
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆868Updated last year
- Repository of YARA rules made by Trellix ATR Team☆576Updated last year
- ☆756Updated last year
- Credential and Red Teaming Defense for Windows Environments☆325Updated 7 months ago
- Test the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-Cradle…☆297Updated 3 years ago
- ☆275Updated last year