mnrkbys / ma2tlLinks
macOS forensic timeline generator using the analysis result DBs of mac_apt
☆93Updated 2 years ago
Alternatives and similar repositories for ma2tl
Users that are interested in ma2tl are comparing it to the libraries listed below
Sorting:
- Forensic Artifact Collection Tool for macOS☆116Updated 4 months ago
- JPCERT/CC public YARA rules repository☆110Updated last month
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆65Updated 2 years ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆55Updated 2 years ago
- Digital Forensics Artifacts Knowledge Base☆88Updated this week
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated last year
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Updated 3 years ago
- acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container.☆112Updated last week
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- Carve file metadata from NTFS index ($I30) attributes☆71Updated last year
- Detection Engineering with YARA☆86Updated last year
- Forensic Artifact Collection Tool Matrix☆91Updated last year
- A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.☆97Updated 2 years ago
- A toolkit for the post-mortem examination of Docker containers from forensic HDD copies☆106Updated last year
- ☆91Updated 4 months ago
- An exercise to practice deobfuscating PowerShell Scripts.☆26Updated 2 years ago
- A C# based tool for analysing malicious OneNote documents☆118Updated 2 years ago
- A YARA & Malware Analysis Toolkit written in Rust.☆84Updated 2 months ago
- Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or event…☆77Updated 4 years ago
- YARA rule analyzer to improve rule quality and performance☆107Updated 8 months ago
- macOS Artifacts☆33Updated 9 months ago
- Script to automate Linux live evidence collection☆28Updated 3 years ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆85Updated last week
- FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), gene…☆98Updated this week
- ESXi Cyber Security Incident Response Script☆25Updated last year
- USN Journal full path builder☆63Updated last year
- ☆19Updated 3 years ago
- A GUI to query the API of abuse.ch.☆70Updated 3 years ago
- ☆67Updated 3 weeks ago
- Forensic tool for acquisition, triage and analysis of remote block devices via iSCSI protocol.☆43Updated last year