jeffbryner / NBDServer
Network Block Device Server for windows with a DFIR/forensic focus.
☆97Updated 7 years ago
Related projects: ⓘ
- An NTFS journal parser☆82Updated 8 years ago
- Library and tools to access the Volume Shadow Snapshot (VSS) format☆109Updated last month
- Digital Forensics Windows Registry (dfWinReg)☆49Updated 4 months ago
- AuditParser☆58Updated 11 years ago
- A Powershell script for frequency analysis of separated values data files.☆17Updated 10 years ago
- Checks with NSRL RDS servers looking for for hash matches☆111Updated 3 years ago
- Decode security descriptors in $Secure on NTFS☆20Updated 2 years ago
- openioc_scan Volatility Framework plugin☆42Updated 8 years ago
- Open source Python library for NTFS analysis☆80Updated 6 years ago
- Yet another registry parser☆128Updated 2 years ago
- Python script to parse the NTFS USN Journal☆105Updated 2 years ago
- ☆37Updated this week
- Command line utility and Python package to ease the (un)mounting of forensic disk images☆116Updated last year
- MantaRay Automated Computer Forensic Triage Tool☆63Updated 5 years ago
- Example programs used in the automating DFIR series☆64Updated 5 years ago
- A better strings utility!☆119Updated last year
- PowerShell scripts for Hard Drive forensics and parsing Windows Artifacts☆56Updated 3 years ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆103Updated last month
- Python tools for IOC (Indicator of Compromise) handling☆96Updated 2 years ago
- ☆57Updated this week
- Recurse through a registry, identifying values with large data -- a registry malware hunter☆43Updated 8 years ago
- Python IOC Editor☆61Updated 9 years ago
- Maps process creation logged by Sysmon uses Google Org Chart API☆24Updated 8 years ago
- ☆64Updated this week
- Cryptowall Tooling & Information☆35Updated 8 years ago
- This is a script module for Bro that encapsulates and detects activity related to the Mandiant APT1 report.☆47Updated 10 years ago
- Queries to parse sysmon event log file with microsoft logparser☆56Updated 9 years ago
- Evidence Fetcher (efetch) is a web-based file explorer, viewer, and analyzer.☆36Updated 4 years ago
- ☆82Updated last year
- Digital Forensics Virtual File System (dfVFS)☆202Updated 4 months ago