QuoSecGmbH / os_timestamps
Explore how Unix-like OS (Linux, BSD, macOS...) modify MACB timestamps and check against POSIX (non-)compliance
☆18Updated last month
Related projects ⓘ
Alternatives and complementary repositories for os_timestamps
- Windows Event Log Knowledge Base☆18Updated last month
- Tool to decompress data from Windows 10 page files and memory dumps, that has been compressed by the Windows 10 memory manager.☆48Updated 5 years ago
- XOR Key Extractor☆48Updated 3 months ago
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆76Updated 2 years ago
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Updated last year
- Userland API monitor for threat hunting☆55Updated 4 years ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆71Updated last week
- Parsing MITRE EDR Evaluation results☆12Updated 5 years ago
- ☆48Updated 4 years ago
- ☆15Updated 2 years ago
- Links to malware-related YARA rules☆14Updated 2 years ago
- A Splunk Technology Add-on to forward filtered ETW events.☆30Updated 4 years ago
- Assorted documentation, scripts and tools☆28Updated last month
- Scripts to aid analysis of files obfuscated with ScatterBee.☆16Updated last year
- NTFS samples☆25Updated 4 years ago
- ☆13Updated 2 years ago
- A collection of my public YARA signatures for various malware families☆29Updated 2 months ago
- Alternative YARA scanning engine☆67Updated 2 years ago
- Python based CLI for MalwareBazaar☆36Updated 3 weeks ago
- Toolset to analyze disks encrypted with McAFee FDE technology☆17Updated 3 years ago
- ☆13Updated 8 years ago
- This repository maintains the SaltStack state files for the REMnux distro.☆39Updated 2 weeks ago
- A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection☆28Updated 4 years ago
- ☆51Updated 6 years ago
- Validates Sigma rules using the JSON schema☆15Updated 8 months ago
- Threat intelligence and threat detection indicators (IOC, IOA)☆53Updated 3 years ago
- YAFRA is a semi-automated framework for analyzing and representing reports about IT Security incidents.☆27Updated 2 years ago
- YARA Language Server☆68Updated this week
- Carve files for MFT entries (eg. blkls output or memory dumps). Recovers filenames (long & short), timestamps ($STD & $FN) and data if re…☆21Updated 5 years ago
- Symbol hash for ELF files☆102Updated 2 years ago