fireeye / BitsParser
☆137Updated 3 months ago
Related projects: ⓘ
- Blueteam operational triage registry hunting/forensic tool.☆142Updated last year
- HXTool is an extended user interface for the FireEye HX Endpoint product. HXTool can be installed on a dedicated server or on your physic…☆79Updated 2 months ago
- evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.☆144Updated 2 years ago
- A Cobalt Strike Scanner that retrieves detected Team Server beacons into a JSON object☆162Updated last year
- ☆168Updated 8 months ago
- A python script developed to process Windows memory images based on triage type.☆259Updated 9 months ago
- Command line access to the Registry☆123Updated last week
- ☆61Updated 3 weeks ago
- ☆84Updated 7 months ago
- Digital Forensics Artifacts Knowledge Base☆71Updated 4 months ago
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆139Updated 2 months ago
- YARA rule analyzer to improve rule quality and performance☆93Updated 9 months ago
- A PowerShell incident response script for quick triage☆75Updated 2 years ago
- Automagically extract forensic timeline from volatile memory dump☆123Updated 4 months ago
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆109Updated 2 years ago
- ☆214Updated 4 months ago
- Dump quarantined files from Windows Defender☆51Updated 2 years ago
- Pushes Sysmon Configs☆89Updated 3 years ago
- This is a set of tools for doing forensics analysis on Microsoft ESE databases.☆123Updated 2 years ago
- Parses amcache.hve files, but with a twist!☆115Updated 2 weeks ago
- A series of PowerShell scripts to automate collection of forensic artefacts in most Incident Response environments☆64Updated 2 years ago
- ☆130Updated 7 months ago
- Public Repo for Atomic Test Harness☆244Updated 2 months ago
- My conference presentations☆66Updated 11 months ago
- Elastic Security Labs releases☆46Updated 3 weeks ago
- Powershell Event Tracing Toolbox☆72Updated 2 years ago
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆62Updated last year
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆266Updated 3 weeks ago
- Active Directory Purple Team Playbook☆103Updated last year
- The Windows Malware Analysis Reversing Core Tools☆88Updated 3 years ago