dnlongen / RegListerLinks
Recurse through a registry, identifying values with large data -- a registry malware hunter
☆44Updated 9 years ago
Alternatives and similar repositories for RegLister
Users that are interested in RegLister are comparing it to the libraries listed below
Sorting:
- Some IR notes☆73Updated 9 years ago
- A Windows Event Processing Utility☆47Updated 7 years ago
- Proof of concept VBA code to add to Normal.dot to put restrictions on Word☆41Updated 8 years ago
- Some dfir stuff☆31Updated 3 years ago
- Various scrips☆12Updated 2 years ago
- Volatility Plugins☆21Updated 10 years ago
- Automated memory forensics analysis☆33Updated 6 years ago
- A Rekall interactive document for a Memory Analysis workshop/course.☆43Updated 8 years ago
- A GC link parser for both linkfiles and jumplists.☆18Updated 8 years ago
- A collection of scripts to initialize a windows VM to run all the malwares!☆105Updated 5 years ago
- A python script used to parse the SAM registry hive.☆74Updated 7 years ago
- A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics☆87Updated 8 years ago
- Frontend for Codex Gigas☆21Updated 8 years ago
- An automated collection and analysis of malware from my honeypots.☆25Updated 7 years ago
- Command line tool for scanning streams within office documents plus xor db attack☆126Updated 2 years ago
- ☆16Updated 10 years ago
- Manage VT Alerts☆62Updated 9 years ago
- Plugins for the Volatility framework☆18Updated 9 years ago
- Queries to parse sysmon event log file with microsoft logparser☆56Updated 10 years ago
- Mystique may be used to discover infection markers that can be used to vaccinate endpoints against malware. It receives as input a malici…☆82Updated 8 years ago
- A warehouse for your malware☆133Updated 12 years ago
- Various DFIR Tools☆26Updated 7 years ago
- Reconstruct process trees from event logs☆147Updated 5 years ago
- ☆46Updated 8 years ago
- Based on the Volatility framework, this script will run various plugins as well as create a timeline, or use YARA/ClamAV/VirusTotal to fi…☆48Updated 8 years ago
- Executes PowerShell from an unmanaged process☆29Updated 10 years ago
- PowerShell scripts for Hard Drive forensics and parsing Windows Artifacts☆56Updated 4 years ago
- Assorted classes and methods for indexing reports and retrieving information from an elastic index☆21Updated 9 years ago
- Automation for VirusTotal☆31Updated 9 years ago
- Automated install scripts for Cuckoo sandbox☆38Updated 7 years ago