obsidianforensics / SQUID
"Fuzzy matching" for SQLite databases
☆29Updated 4 years ago
Alternatives and similar repositories for SQUID:
Users that are interested in SQUID are comparing it to the libraries listed below
- Useful scripts, rules etc. for use with YARA☆27Updated 4 years ago
- Artefacts from various retefe campaigns☆10Updated 6 years ago
- Recurse through a registry, identifying values with large data -- a registry malware hunter☆45Updated 8 years ago
- Multiple rules for yara-project for detect compiler/packer/protector☆33Updated 5 years ago
- misc scripts☆36Updated 6 years ago
- onigiri - remote malware triage script☆24Updated 9 years ago
- Performs OCR on image files and scans them for matches to YARA rules☆41Updated 6 years ago
- Why hunt when you can seine?☆21Updated 9 years ago
- Server for receiving autorun data from the clients☆13Updated 7 years ago
- Various scrips☆12Updated 2 years ago
- Command-line Interface for Binar.ly☆37Updated 8 years ago
- Extract information from MISP via the API☆15Updated 8 years ago
- Discover potential timestamps within the Windows Registry☆18Updated 11 years ago
- Various DFIR Tools☆26Updated 6 years ago
- Maltego Transform to put entities into MISP events☆27Updated 3 years ago
- Python libary to normalize Yara signatures☆19Updated 4 years ago
- openioc_scan Volatility Framework plugin☆43Updated 9 years ago
- Volatility Plugins☆21Updated 10 years ago
- Binaries for the log2timeline projects and dependencies☆39Updated 7 months ago
- Recover event log entries from an image by heurisitically looking for record structures.☆27Updated 9 years ago
- BSidesLV 2015 Exploit Kit Analysis Workshop Files☆27Updated 9 years ago
- Unpack MIME attachments from a file and check them against virustotal.com☆44Updated 9 years ago
- An active domain name query tool to help keep track of domain name movements...☆15Updated 4 years ago
- Digital Forensics Windows Registry (dfWinReg)☆51Updated 4 months ago
- This is a copy of the Registry Decoder Live repository from Google Code☆9Updated 9 years ago
- Some dfir stuff☆31Updated 3 years ago
- tracy - a system call tracer and injector. Find us in #tracy on irc.freenode.net☆33Updated last year
- Yara Scanner For IMAP Feeds and saved Streams☆28Updated 5 years ago
- ☆36Updated 8 years ago
- Tool to parse SRU database☆24Updated 7 years ago