RustyBlue is a rust implementation of DeepblueCLI, a forensics log analyzer for finding evidence of compromise from windows event logs.
☆72Oct 13, 2022Updated 3 years ago
Alternatives and similar repositories for RustyBlue
Users that are interested in RustyBlue are comparing it to the libraries listed below
Sorting:
- ☆25Feb 13, 2021Updated 5 years ago
- This is a repository for reporting any issues in any of my software☆13May 15, 2018Updated 7 years ago
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆215Updated this week
- Sample evtx files to use for testing hayabusa detection rules☆65Nov 5, 2025Updated 4 months ago
- ☆21May 8, 2022Updated 3 years ago
- ARM Exploit 開発のためのトレーニングリポジトリ☆19May 23, 2020Updated 5 years ago
- ペネトレーションテストについて☆75Aug 12, 2021Updated 4 years ago
- ☆37Oct 4, 2020Updated 5 years ago
- ☆23Oct 9, 2024Updated last year
- FileSigExtractor is a python based tool which extracts the file signatures of all files within a directory and writes the output to a CSV…☆10Jul 15, 2023Updated 2 years ago
- A tool for fetching DFIR and other GitHub tools.☆26Aug 2, 2025Updated 7 months ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆43Sep 21, 2023Updated 2 years ago
- WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)☆779Feb 3, 2023Updated 3 years ago
- macOS Artifact Intelligence Tool