mnrkbys / ma2tlLinks
macOS forensic timeline generator using the analysis result DBs of mac_apt
☆95Updated 2 years ago
Alternatives and similar repositories for ma2tl
Users that are interested in ma2tl are comparing it to the libraries listed below
Sorting:
- Forensic Artifact Collection Tool for macOS☆114Updated last month
- JPCERT/CC public YARA rules repository☆110Updated 9 months ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆54Updated 2 years ago
- Digital Forensics Artifacts Knowledge Base☆86Updated last year
- WLEAPP is an open source project that aims to parse Windows OS artifacts for the purpose of triage analysis.☆32Updated last year
- Quick ESXi Log Parser☆25Updated last week
- A YARA & Malware Analysis Toolkit written in Rust.☆48Updated last month
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆69Updated 2 years ago
- Chrome Logs Events and Protobuf Parser☆39Updated 2 years ago
- A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. P…☆28Updated 2 years ago
- Just Another broken Registry Parser (JARP)☆16Updated last year
- CryptnetURLCacheParser is a tool to parse CryptAPI cache files☆18Updated last year
- The core backend server handling API requests and task management☆46Updated last week
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆27Updated 3 years ago
- Information about the open-source-dfir slack community☆30Updated 2 years ago
- An exercise to practice deobfuscating PowerShell Scripts.☆26Updated 2 years ago
- macOS Artifacts☆31Updated 6 months ago
- Forensic Artifact Collection Tool Matrix☆89Updated 10 months ago
- ☆68Updated last month
- USN Journal full path builder☆61Updated 11 months ago
- A toolkit for the post-mortem examination of Docker containers from forensic HDD copies☆105Updated last year
- ☆88Updated last month
- Remote access and Antivirus Logging Database☆42Updated last year
- ☆21Updated 6 months ago
- Detection Engineering with YARA☆87Updated last year
- A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.☆97Updated 2 years ago
- acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container.☆109Updated last week
- ☆38Updated 4 years ago
- A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhanc…☆57Updated 2 months ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆65Updated 3 years ago