laciKE / EsetLogParser
Python script for parsing ESET (NOD32) virlog.dat file.
☆14Updated 7 years ago
Alternatives and similar repositories for EsetLogParser:
Users that are interested in EsetLogParser are comparing it to the libraries listed below
- ☆34Updated 2 years ago
- Manipulate timestamps on NTFS☆50Updated 10 years ago
- Generate YARA rules for OOXML documents.☆38Updated last year
- ProcDot Malware Sandbox☆24Updated 5 months ago
- ☆33Updated 3 years ago
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆31Updated 4 years ago
- A set of tools for collecting forensic information☆26Updated 5 years ago
- Trace ScriptBlock execution for powershell v2☆40Updated 5 years ago
- Binary commandline executable to parse ETL files☆67Updated 6 years ago
- ☆90Updated 2 years ago
- A collection of useful PowerShell tools to collect, organize, and visualize Sysmon event data☆39Updated 5 years ago
- Generates YARA rules to detect malware using API hashing☆17Updated 4 years ago
- Get intelligence info (tags, mitre techniques, yara and more) and find similar malware in a fast and easy way☆18Updated 2 years ago
- Threat Mitigation Strategies☆25Updated last year
- Presentation materials for talks I've given.☆20Updated 5 years ago
- Repository for LNK stuff☆30Updated 2 years ago
- A powershell parser for https://github.com/ufrisk/MemProcFS☆44Updated 3 years ago
- POSHSPY backdoor code☆43Updated 8 years ago
- AdHoc solutions☆48Updated last year
- Windows.EDB Browser☆56Updated 2 years ago
- Documentation and parsers for different anti-virus quarantine formats.☆42Updated 4 years ago
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- Babel-Shellfish deobfuscates and scans Powershell scripts on real-time right before each line execution.☆43Updated 6 years ago
- A script to assist in processing forensic RAM captures for malware triage☆27Updated 4 years ago
- ☆23Updated last year
- ☆15Updated 3 years ago
- Emulates the VirusTotal "vt" YARA module for livehunt rule debugging/testing☆21Updated last year
- A collection of Indicators of Compromise (IoCs), most aligning with samples derived from the signatures in the YARA-Signatures repo☆29Updated 4 years ago
- OSSEM Modular☆27Updated 4 years ago
- Repository of tools, YARA rules, and code-snippets from Stairwell's research team.☆22Updated last year