Dump quarantined files from Windows Defender
☆81Apr 6, 2022Updated 4 years ago
Alternatives and similar repositories for defender-dump
Users that are interested in defender-dump are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated 2 years ago
- Multi-quarantine extractor☆59Mar 3, 2026Updated 4 months ago
- an open source python deobfuscator for pyobfuscate.com☆39Jul 28, 2024Updated last year
- A DFIR Incident Response AI bot using local Ollama LLM to derrive automated findings from logs☆16Jan 17, 2026Updated 6 months ago
- Utilizing DLang For Offensive Operations.☆15May 29, 2025Updated last year
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- This tool aims at parsing Microsoft Protection logs to provide relevant data to forensic analysts during incident responses.☆22Sep 30, 2022Updated 3 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆43Jul 18, 2022Updated 4 years ago
- Capture. Detonate. Collect☆14Sep 20, 2024Updated last year
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- ☆21May 8, 2022Updated 4 years ago
- This is a repository for reporting any issues in any of my software☆14May 15, 2018Updated 8 years ago
- Carve file metadata from NTFS index ($I30) attributes☆73May 25, 2026Updated 2 months ago
- A runtime Assembly dumper for powershell to combat the rise in .net based crypters and malware.☆18Aug 26, 2025Updated 11 months ago
- Fork this repo! Do a Pull Request! As many times as you want! Learn the ins and outs of how to contribute to GitHub! Make your mistakes h…☆15Jun 21, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆69Sep 13, 2023Updated 2 years ago
- ☆37Nov 8, 2024Updated last year
- Thor Artifacts for Velociraptor☆19Dec 2, 2025Updated 7 months ago
- Disassemble V8 Ignition bytecode.☆11Jan 2, 2024Updated 2 years ago
- USN Journal full path builder☆69Apr 16, 2026Updated 3 months ago
- A fucking real shellcode loader with a GUI. Work-in-Progress.☆81Jun 25, 2025Updated last year
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆330Sep 3, 2023Updated 2 years ago
- ☆22Jan 31, 2023Updated 3 years ago
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆34Jun 5, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆10Apr 19, 2026Updated 3 months ago
- ☆22Aug 16, 2025Updated 11 months ago
- Near compile-time string obfuscation for Golang☆13Oct 3, 2023Updated 2 years ago
- ☆23Mar 12, 2025Updated last year
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆118Jan 26, 2022Updated 4 years ago
- Anti-Debugging (Self-Debugging)☆17Sep 6, 2025Updated 10 months ago
- Process Hollowing in Rust with Process Executable Relocation Support for both 32 and 64 bit architecture environments.☆24Jan 6, 2025Updated last year
- extract chromium-based browser's cookies using chrome's remote debugging without admin rights☆22Nov 3, 2024Updated last year
- A tool to read and encrypt shellcode (.bin) and display encrypted bytes as output to be copied in Injectors for evasion☆16Dec 21, 2021Updated 4 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Mount VSCs with ease!☆18Apr 28, 2026Updated 2 months ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆265Oct 29, 2025Updated 8 months ago
- A collaboration effort by the DFIR community to provide definitions (sometimes multiple) for common forensic terms!☆26Dec 1, 2022Updated 3 years ago
- Demonstrate the new FileDispositionInfoEx behavior☆15Nov 6, 2017Updated 8 years ago
- HardwareTurningPoint, Fully Go Compatible Hardware Breakpoint☆14Jan 30, 2025Updated last year
- Menu for Thor scanner lite☆20Oct 24, 2025Updated 9 months ago
- This script will generate hashes (MD5, SHA1, SHA256), submit the MD5 to Virus Total, and produce a text file with the results.☆15Jul 13, 2023Updated 3 years ago