joachimmetz / artifacts
ForensicArtifacts.com Artifact Repository
☆11Updated last month
Alternatives and similar repositories for artifacts:
Users that are interested in artifacts are comparing it to the libraries listed below
- ☆48Updated last week
- A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhanc…☆55Updated 3 weeks ago
- Example programs used in the automating DFIR series☆64Updated 5 years ago
- 2021 SANS DFIR Summit: Greppin' Logs☆21Updated 3 years ago
- Carbon Black Feeds☆72Updated last year
- Different DFIR and CTI utilities☆36Updated 4 years ago
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆106Updated last year
- Tools from WFA 4/e, timeline tools, etc.☆134Updated 11 months ago
- BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.☆42Updated 2 years ago
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆194Updated 5 months ago
- This is a set of tools for doing forensics analysis on Microsoft ESE databases.☆124Updated 3 years ago
- ☆5Updated 3 months ago
- Scripts to facilitate filtering with Plaso☆125Updated 4 years ago
- Documentation repository☆44Updated 5 months ago
- Chrome Logs Events and Protobuf Parser☆36Updated 2 years ago
- Dump of organized knowledge on DFIR☆133Updated 3 years ago
- A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.☆203Updated last week
- Get all my software☆148Updated last month
- Tools to automate and/or expedite response.☆113Updated 7 months ago
- This repository is a collection of EnScript code samples for use in the OpenText EnCase application.☆53Updated last month
- Practical Orientation Of MVISION EDR Query Language☆34Updated 2 years ago
- Collection of useful, up to date, Carbon Black Response Queries☆83Updated 4 years ago
- "Evolving AppCompat/AmCache data analysis beyond grep"☆200Updated 3 years ago
- Collection of scripts provided for public use☆34Updated 3 months ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆72Updated last year
- ATT&CK Remote Threat Hunting Incident Response☆200Updated 2 months ago
- ☆13Updated 2 years ago
- A framework for orchestrating forensic collection, processing and data export☆305Updated last week
- A fork of The Sleuthkit with Pooled Storage and APFS support. See https://www.youtube.com/watch?v=k1XPillJ7aw for more info and usage.☆26Updated 5 years ago
- Yet another registry parser☆130Updated 2 years ago