kacos2000 / Prefetch-BrowserLinks
Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's
☆62Updated 5 months ago
Alternatives and similar repositories for Prefetch-Browser
Users that are interested in Prefetch-Browser are comparing it to the libraries listed below
Sorting:
- Simple PowerShell script to enable process scanning with Yara.☆93Updated 2 years ago
- Windows.EDB Browser☆56Updated 2 years ago
- Yara Rules for Modern Malware☆77Updated last year
- Create a cool process tree like https://twitter.com/ACEResponder.☆35Updated 2 years ago
- PS-TrustedDocuments: PowerShell script to handle information on trusted documents for Microsoft Office☆35Updated 2 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆31Updated 2 years ago
- Evtx Log (xml) Browser☆56Updated 2 years ago
- Contains compiled binaries of Volatility☆33Updated 2 weeks ago
- ☆45Updated last year
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆41Updated 8 months ago
- ☆14Updated last year
- ESXi Cyber Security Incident Response Script☆22Updated 8 months ago
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆27Updated 2 years ago
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆68Updated last year
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆33Updated last month
- ☆33Updated 3 years ago
- A C# based tool for analysing malicious OneNote documents☆113Updated 2 years ago
- Quick ESXi Log Parser☆20Updated 4 months ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated last year
- a tiny program to consume from ETW providers for research☆48Updated 4 months ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆32Updated last year
- A small util to brute-force prefetch hashes☆77Updated 2 years ago
- ☆34Updated 2 years ago
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆36Updated 3 months ago
- Default Detections for EDR☆96Updated last year
- A proof-of-concept re-assembler for reverse VNC traffic.☆25Updated 2 years ago
- ☆19Updated 2 years ago
- Quickly search for references to a GUID in DLLs, EXEs, and drivers☆74Updated 3 years ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆53Updated last year
- Placeholder for my detection repo and misc detection engineering content☆43Updated last year