QuoSecGmbH / os_timestampsLinks
Explore how Unix-like OS (Linux, BSD, macOS...) modify MACB timestamps and check against POSIX (non-)compliance
☆19Updated 7 months ago
Alternatives and similar repositories for os_timestamps
Users that are interested in os_timestamps are comparing it to the libraries listed below
Sorting:
- NTFS samples☆25Updated 4 years ago
- Command line access to the Registry☆147Updated last month
- Digital Forensics Artifacts Knowledge Base☆81Updated last year
- Psinfo is a Volatility plugin which collects the process related information from the VAD (Virtual Address Descriptor) and PEB (Process E…☆36Updated 8 years ago
- Userland API monitor for threat hunting☆58Updated 5 years ago
- A Splunk Technology Add-on to forward filtered ETW events.☆30Updated 4 years ago
- Parsing MITRE EDR Evaluation results☆12Updated 6 years ago
- Carve files for MFT entries (eg. blkls output or memory dumps). Recovers filenames (long & short), timestamps ($STD & $FN) and data if re…☆21Updated 6 years ago
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Updated 2 years ago
- Windows Event Log Knowledge Base☆24Updated 7 months ago
- Alternative YARA scanning engine☆70Updated 2 years ago
- Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.☆25Updated 2 years ago
- Script that checks for available updates for the most commonly used Digital Forensics tools☆59Updated 4 years ago
- Windows link file (shortcuts) examiner☆68Updated 11 months ago
- Simple yara rule manager☆66Updated 2 years ago
- Extract compressed memory pages from page-aligned data☆45Updated 6 years ago
- Carve file metadata from NTFS index ($I30) attributes☆66Updated last year
- Sample staging & detonation utility to be used in combination with Cuckoo Sandbox.☆11Updated 3 months ago
- Yara Based Detection Engine for web browsers☆47Updated 3 years ago
- Documentation and parsers for different anti-virus quarantine formats.☆42Updated 4 years ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆60Updated 2 years ago
- Core server components for Assemblyline 4 (Alerter, dispatcher, expiry, ingester, scaler, updater, ...)☆21Updated this week
- Merge all Yara rules from official Yara github repository in one .yar file☆29Updated 6 years ago
- Tool to decompress data from Windows 10 page files and memory dumps, that has been compressed by the Windows 10 memory manager.☆50Updated 6 years ago
- Python based CLI for MalwareBazaar☆37Updated 7 months ago
- A guide on how to write fast and memory friendly YARA rules☆144Updated 3 months ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆73Updated last year
- ConventionEngine - A Yara Rulepack for PDB Path Hunting☆38Updated 2 years ago
- Windows file metadata / forensic tool.☆18Updated 8 months ago
- ☆22Updated 7 months ago