Psmths / windows-forensic-artifactsLinks
Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!
☆443Updated last year
Alternatives and similar repositories for windows-forensic-artifacts
Users that are interested in windows-forensic-artifacts are comparing it to the libraries listed below
Sorting:
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆689Updated 2 months ago
- ☆170Updated 2 years ago
- CLI tools for forensic investigation of Windows artifacts☆348Updated 5 months ago
- DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital For…☆396Updated 3 weeks ago
- A centralized and enhanced memory analysis platform☆512Updated 5 months ago
- Awesome list of keywords and artifacts for Threat Hunting sessions☆622Updated 4 months ago
- A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat in…☆430Updated last week
- Repository for sharing examples of our artifacts data and for use in new analyst recruitment.☆108Updated 8 months ago
- Map tracking ransomware, by OCD World Watch team☆480Updated 9 months ago
- The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifa…☆632Updated last month
- Practical Windows Forensics Training☆703Updated last year
- Windows Malware Investigation Scripts & Docs☆85Updated last year
- Memory acquisition for Linux that makes sense.☆215Updated 2 years ago
- Harness the power of Splunk for your investigations☆145Updated 2 months ago
- PowerShell tools to help defenders hunt smarter, hunt harder.☆448Updated last month
- A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as …☆420Updated 4 months ago
- An Archive of Ransomware Notes Past and Present Collected by Zscaler ThreatLabz☆393Updated last month
- A curated list of awesome Memory Forensics for DFIR☆506Updated 10 months ago
- Windows Forensics Environment Builder☆169Updated 3 weeks ago
- A GUI and CLI tool for removing bloat from executables☆436Updated 5 months ago
- Advanced Bash script designed for conducting digital forensics on Linux systems☆144Updated last year
- ☆380Updated this week
- Purpleteam scripts simulation & Detection - trigger events for SOC detections☆192Updated last year
- This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom …☆773Updated last week
- Forensics Wiki, a wiki devoted to information about digital forensics (also known as computer forensics)☆303Updated last week
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆211Updated this week
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆341Updated 3 weeks ago
- This repository contains sample programs that mimick behavior found in real-world malware. The goal is to provide source code that can be…☆676Updated last year
- Documentation and scripts to properly enable Windows event logs.☆649Updated 2 months ago
- Rapidly Search and Hunt through Linux Forensics Artifacts☆201Updated last year