Miscellaneous Scripts
☆17Sep 11, 2020Updated 5 years ago
Alternatives and similar repositories for 4n6_misc
Users that are interested in 4n6_misc are comparing it to the libraries listed below
Sorting:
- Yet another registry parser☆138Apr 15, 2022Updated 3 years ago
- Indicators of compromise relating to our report on APT10's targeting of global MSPs☆10Sep 26, 2017Updated 8 years ago
- Tool to extract the $UsnJrnl from an NTFS volume☆109Jul 30, 2019Updated 6 years ago
- ☆13Nov 10, 2020Updated 5 years ago
- ☆11Mar 12, 2021Updated 4 years ago
- Carve NTFS USN records from binary data☆27May 21, 2017Updated 8 years ago
- Parses the WMI object database....looking for persistence☆34Dec 12, 2019Updated 6 years ago
- Writeups for CTF that took place in 2015.☆13Mar 22, 2016Updated 9 years ago
- macOS Artifact Intelligence Tool☆13Apr 30, 2019Updated 6 years ago
- A repo containing some tooling build to assist with reverse engineering malware samples☆15Jul 22, 2023Updated 2 years ago
- Tools for parsing Forensic images☆41Dec 14, 2018Updated 7 years ago
- Different DFIR and CTI utilities☆39May 13, 2020Updated 5 years ago
- AuditParser☆60Aug 28, 2013Updated 12 years ago
- Page File analysis tools.☆131Dec 3, 2015Updated 10 years ago
- An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.☆21Nov 13, 2022Updated 3 years ago
- Detection rules to look for Log4J usage and exploitation☆18Jun 21, 2025Updated 8 months ago
- ☆23Aug 1, 2020Updated 5 years ago
- Site for IWS book content☆17Oct 28, 2018Updated 7 years ago
- Win 10/11 related research☆198Dec 19, 2023Updated 2 years ago
- Tools from WFA 4/e, timeline tools, etc.☆145Feb 29, 2024Updated 2 years ago
- ☆22Dec 22, 2020Updated 5 years ago
- A collection of Volatility Framework plugins.☆26Aug 29, 2013Updated 12 years ago
- Blazescan is a linux webserver malware scanning and incident response tool, with built in support for cPanel servers, but will run on any…☆60Nov 10, 2018Updated 7 years ago
- Plugins to add funtionality to ProcDOT. http://www.procdot.com☆25Sep 26, 2023Updated 2 years ago
- ☆26Aug 6, 2021Updated 4 years ago
- Blueteam operational triage registry hunting/forensic tool.☆149Sep 2, 2025Updated 6 months ago
- Initial triage of Windows Event logs☆106Jun 16, 2024Updated last year
- Binary commandline executable to parse ETL files☆69Jun 7, 2018Updated 7 years ago
- Tool to parse SRU database☆25Mar 1, 2018Updated 8 years ago
- IcedID Decryption Tool☆28May 7, 2021Updated 4 years ago
- Windows registry samples☆24Nov 18, 2018Updated 7 years ago
- CAPE Auto-Hardened Installer☆26Jan 28, 2026Updated last month
- 🕳️ Proof of Concept exploits and their descriptions for various products☆25Nov 12, 2024Updated last year
- .NET deobfuscator and unpacker (with a control flow unflattener for DoubleZero added).☆29Jun 14, 2022Updated 3 years ago
- Accompanying PowerShell Modules for DevSec Defense Presentation☆30Apr 15, 2018Updated 7 years ago
- Gunslinger is used to hunt for Magecart sites using URLScan's API☆31Mar 15, 2022Updated 3 years ago
- Simple Powershell scripts to collect all Windows Event Logs from a host and parse them into one CSV timeline.☆32Oct 13, 2018Updated 7 years ago
- Scripts to integrate DFIR-IRIS, MISP and TimeSketch☆35Feb 2, 2022Updated 4 years ago
- pcapdj - dispatch pcap files☆46Jul 28, 2020Updated 5 years ago