AuditParser
☆60Aug 28, 2013Updated 12 years ago
Alternatives and similar repositories for AuditParser
Users that are interested in AuditParser are comparing it to the libraries listed below
Sorting:
- ☆109Nov 21, 2013Updated 12 years ago
- ☆207May 3, 2023Updated 2 years ago
- ☆82Jul 5, 2016Updated 9 years ago
- Tools from WFA 4/e, timeline tools, etc.☆145Feb 29, 2024Updated 2 years ago
- ☆46Jun 1, 2023Updated 2 years ago
- ☆280Apr 6, 2023Updated 2 years ago
- ☆134Jun 11, 2021Updated 4 years ago
- ☆432May 3, 2023Updated 2 years ago
- Miscellaneous Scripts☆17Sep 11, 2020Updated 5 years ago
- Carve NTFS USN records from binary data☆27May 21, 2017Updated 8 years ago
- Tools for parsing Forensic images☆41Dec 14, 2018Updated 7 years ago
- parser for Google search strings☆40Sep 14, 2019Updated 6 years ago
- Automating forensic data extraction, reduction, and overall triage of cold disk and memory images.☆21Mar 12, 2019Updated 7 years ago
- NSRL BloomFilter, Mandiant BloomFilter, Hyperloglog Malware Data Structure☆15Mar 14, 2014Updated 12 years ago
- Fix acquired .evt - Windows Event Log files (Forensics)☆18Mar 29, 2016Updated 9 years ago
- Binary property list (plist) parser☆54Nov 13, 2018Updated 7 years ago
- Technical add-on to ingest json formatted volatility memory analysis plugin outputs☆13May 21, 2018Updated 7 years ago
- Quick script to build host or investigation timelines using Carbon Black Response☆12Sep 25, 2018Updated 7 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 9 years ago
- Example programs used in the automating DFIR series☆63Mar 4, 2019Updated 7 years ago
- Publicly shareable windows event log message data☆28Nov 29, 2019Updated 6 years ago
- Indices for courses in SANS' Network Security Operations curriculum☆17Feb 5, 2016Updated 10 years ago
- Public Landing Page☆16Jan 7, 2023Updated 3 years ago
- Container for assorted volatility plugins.☆23Oct 22, 2013Updated 12 years ago
- Kali Linux fresh installation setup scripts.☆14Feb 10, 2017Updated 9 years ago
- An efficient tool for extracting files, directories, and alternate data streams directly from NTFS image files.☆22Mar 12, 2026Updated last week
- Ponmocup Indicators of Compromise☆11Feb 4, 2016Updated 10 years ago
- OS Lockdown☆13Nov 21, 2017Updated 8 years ago
- Parser for Windows Scheduled Task files.☆13Apr 26, 2023Updated 2 years ago
- Registry Miner☆14Apr 10, 2018Updated 7 years ago
- Extracts indicators of compromise (IOCs), including domain names, IPv4 addresses, email addresses, and hashes, from text.☆11Dec 10, 2017Updated 8 years ago
- command line tool to use the DNSDB Flexible Search API extensions.☆16Aug 5, 2024Updated last year
- Repository of Cofense Coronavirus Phishing Yara Rules (details can be found here: https://cofense.com/solutions/topic/coronavirus-infocen…☆10Jul 7, 2020Updated 5 years ago
- An informational repo about hunting for adversaries in your IT environment.☆14Apr 10, 2017Updated 8 years ago
- Python OpenIOC Editor☆18Dec 28, 2015Updated 10 years ago
- Tool suite for inspecting NTFS artifacts.☆226Nov 1, 2023Updated 2 years ago
- A tool for simplifying the process of researching IOCs.☆25Sep 24, 2021Updated 4 years ago
- Create machine images containing the Guacamole remote desktop gateway☆11Updated this week
- Placeholder for IRIS-H Digital Forensics Tool☆15May 30, 2018Updated 7 years ago