herosi / triage-collector
☆22Updated 5 months ago
Alternatives and similar repositories for triage-collector:
Users that are interested in triage-collector are comparing it to the libraries listed below
- ☆34Updated 2 years ago
- ☆33Updated 3 years ago
- Modular malware analysis artifact collection and correlation framework☆53Updated 11 months ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆58Updated 2 years ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated last year
- ETW forensic tool for Volatility3 plugin☆11Updated 4 months ago
- Quick ESXi Log Parser☆16Updated 2 months ago
- Winterfell hunt is a python script to perform auto threat hunting for malicious activities in windows OS based on collected data by winte…☆15Updated 4 years ago
- Reads and prints information from the website MalAPI.io☆19Updated 2 years ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆76Updated last year
- Links to malware-related YARA rules☆15Updated 2 years ago
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆26Updated 2 years ago
- Scripts, Yara rules and other files developed during malware investigations☆25Updated 2 years ago
- ☆14Updated 2 years ago
- ShellSweeping the evil.☆52Updated 9 months ago
- Collection of Malware Lures☆23Updated 3 years ago
- Python based CLI for MalwareBazaar☆36Updated 4 months ago
- ☆20Updated last week
- Windows file metadata / forensic tool.☆18Updated 6 months ago
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Updated 2 years ago
- Collection of generic YARA rules☆15Updated 9 months ago
- Just Another broken Registry Parser (JARP)☆16Updated 10 months ago
- Surface Analysis System on Cloud☆19Updated last year
- A pure PowerShell/ .NET DFIR capability that dumps the Windows SRUM (System Resource Usage Monitor) database to CSVs for analysis.☆13Updated 3 years ago
- Scripts and tools accompanying HP Threat Research blog posts and reports.☆50Updated 11 months ago
- Scripts and lists to help generate YARA friendly string mutations☆21Updated last year
- Generate YARA rules for OOXML documents.☆38Updated last year
- ☆19Updated 2 months ago
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆44Updated 2 years ago
- Create a cool process tree like https://twitter.com/ACEResponder.☆35Updated 2 years ago