Psmths / windows-forensic-artifacts
Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!
☆324Updated 6 months ago
Alternatives and similar repositories for windows-forensic-artifacts:
Users that are interested in windows-forensic-artifacts are comparing it to the libraries listed below
- ☆156Updated last year
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆588Updated last week
- CLI tools for forensic investigation of Windows artifacts☆325Updated 4 months ago
- A curated list of awesome Memory Forensics for DFIR☆396Updated last week
- The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifa…☆582Updated 3 months ago
- Awesome list of keywords and artifacts for Threat Hunting sessions☆534Updated 2 weeks ago
- A centralized and enhanced memory analysis platform☆432Updated last month
- Practical Windows Forensics Training☆647Updated last year
- A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as …☆389Updated 2 months ago
- Map tracking ransomware, by OCD World Watch team☆426Updated this week
- Harness the power of Splunk for your investigations☆92Updated 3 months ago
- Advanced Bash script designed for conducting digital forensics on Linux systems☆138Updated 10 months ago
- ☆514Updated 4 months ago
- A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat in…☆241Updated this week
- DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital For…☆176Updated last week
- PurpleLab is an efficient and readily deployable lab solution, providing a swift setup for cybersecurity professionals to test detection…☆566Updated last week
- ☆195Updated last year
- Memory acquisition for Linux that makes sense.☆178Updated last year
- Documentation and scripts to properly enable Windows event logs.☆590Updated last year
- Windows Forensics Environment Builder☆131Updated last month
- The Volatility Collaborative GUI☆237Updated this week
- ThreatSeeker: Threat Hunting via Windows Event Logs☆119Updated last year
- Forensics Wiki, a wiki devoted to information about digital forensics (also known as computer forensics)☆263Updated 9 months ago
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆604Updated 8 months ago
- Awesome Security lists for SOC/CERT/CTI☆861Updated this week
- Parses $MFT from NTFS file systems☆221Updated 2 weeks ago
- An Archive of Ransomware Notes Past and Present Collected by Zscaler ThreatLabz☆342Updated last week
- TRACE is a digital forensic analysis tool that provides a user-friendly interface for investigating disk images.☆156Updated 3 weeks ago
- Windows Malware Investigation Scripts & Docs☆74Updated 3 months ago
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆278Updated 6 months ago