Velocidex / go-ese
Go implementation of an Extensible Storage Engine parser
☆29Updated last week
Alternatives and similar repositories for go-ese:
Users that are interested in go-ese are comparing it to the libraries listed below
- ☆33Updated 2 years ago
- a tiny program to consume from ETW providers for research☆46Updated last month
- A Dissect module implementing a parser for Microsofts Extensible Storage Engine Database (ESEDB), used for example in Active Directory, E…☆18Updated 3 weeks ago
- Parser for Windows PowerShell script block logs☆13Updated last month
- Simple PowerShell script to enable process scanning with Yara.☆91Updated 2 years ago
- PS-TrustedDocuments: PowerShell script to handle information on trusted documents for Microsoft Office☆34Updated last year
- PowerShell script that abuses browser bookmark synchronization as a mechanism for sending and receiving data between systems.☆15Updated 2 years ago
- Links to malware-related YARA rules☆14Updated 2 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- A golang implementation of a prefetch parser.☆19Updated 5 months ago
- ☆44Updated last year
- Emulates the VirusTotal "vt" YARA module for livehunt rule debugging/testing☆21Updated last year
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆72Updated 3 years ago
- Hunt for SQLite files used by various applications☆10Updated this week
- ShellSweeping the evil.☆52Updated 8 months ago
- ☆34Updated 2 years ago
- ☆45Updated last year
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- THOR Thunderstorm Collectors☆24Updated last week
- Utility to inject honey tokens into lsass.☆27Updated 8 years ago
- C# User Simulation☆32Updated 2 years ago
- Active Directory Toolkit☆20Updated 5 years ago
- ☆23Updated last year
- A set of tools for collecting forensic information☆26Updated 4 years ago
- Repo containing my public talks☆23Updated last year
- Python DPAPI NG Decryptor for non-Windows Platforms☆57Updated 2 months ago
- Trace ScriptBlock execution for powershell v2☆40Updated 5 years ago
- ☆10Updated last year
- Yara rules☆20Updated last year
- Windows registry samples☆23Updated 6 years ago