obsidianforensics / SQUID
"Fuzzy matching" for SQLite databases
☆29Updated 4 years ago
Alternatives and similar repositories for SQUID:
Users that are interested in SQUID are comparing it to the libraries listed below
- Recover event log entries from an image by heurisitically looking for record structures.☆27Updated 9 years ago
- Email Abuse - A Versatile Software for Email review, analysis and reporting☆21Updated 9 years ago
- AFF4 Standard Documents☆28Updated 3 years ago
- Performs OCR on image files and scans them for matches to YARA rules☆41Updated 6 years ago
- onigiri - remote malware triage script☆24Updated 9 years ago
- Server for receiving autorun data from the clients☆13Updated 7 years ago
- Scripts to extract compound bplists in the iOS -> KnowledgeC.db -> structuredmetadata table.☆24Updated 5 years ago
- Useful scripts, rules etc. for use with YARA☆27Updated 4 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆42Updated 4 years ago
- This repository is a curated list of pro bono incident response entities.☆20Updated last year
- Windows Thingies in Python for live use.☆24Updated 5 years ago
- Some dfir stuff☆31Updated 3 years ago
- This is a copy of the Registry Decoder Live repository from Google Code☆9Updated 9 years ago
- A Windows Event Processing Utility☆46Updated 7 years ago
- Various DFIR Tools☆26Updated 6 years ago
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated 2 years ago
- Maltego Transform to put entities into MISP events☆27Updated 3 years ago
- This project contains code for comparing or ranking APT capabilities and operational capacity. The metrics are meant to quantify, rank, o…☆35Updated 6 years ago
- Python tool for bulk PDF feature extraction. This tool is a prototype.☆24Updated 8 years ago
- Binaries for the log2timeline projects and dependencies☆39Updated 6 months ago
- Tool to parse SRU database☆24Updated 7 years ago
- openioc_scan Volatility Framework plugin☆42Updated 9 years ago
- Extract information from MISP via the API☆15Updated 8 years ago
- misc scripts☆36Updated 6 years ago
- Metadata Inspection Database Alerting System☆42Updated 11 years ago
- Decode security descriptors in $Secure on NTFS☆20Updated 3 years ago
- Yara Scanner For IMAP Feeds and saved Streams☆28Updated 5 years ago
- Multiple rules for yara-project for detect compiler/packer/protector☆33Updated 5 years ago
- Discover potential timestamps within the Windows Registry☆18Updated 10 years ago
- incident response tool for iOS devices☆49Updated 2 years ago