obsidianforensics / SQUID
"Fuzzy matching" for SQLite databases
☆29Updated 4 years ago
Alternatives and similar repositories for SQUID:
Users that are interested in SQUID are comparing it to the libraries listed below
- Useful scripts, rules etc. for use with YARA☆27Updated 4 years ago
- Digital Forensics Windows Registry (dfWinReg)☆49Updated last month
- Multiple rules for yara-project for detect compiler/packer/protector☆33Updated 5 years ago
- Carves EXEs from given data files, using intelligent carving based upon PE headers☆37Updated 7 years ago
- Why hunt when you can seine?☆21Updated 9 years ago
- Resources for HFS+ Forensics☆35Updated 9 years ago
- Performs OCR on image files and scans them for matches to YARA rules☆40Updated 6 years ago
- tracy - a system call tracer and injector. Find us in #tracy on irc.freenode.net☆33Updated 11 months ago
- Unpack MIME attachments from a file and check them against virustotal.com☆45Updated 8 years ago
- AFF4 Standard Documents☆28Updated 3 years ago
- Discover potential timestamps within the Windows Registry☆18Updated 10 years ago
- Scripts to extract compound bplists in the iOS -> KnowledgeC.db -> structuredmetadata table.☆22Updated 5 years ago
- Volatility Plugins☆21Updated 9 years ago
- A Windows Event Processing Utility☆46Updated 7 years ago
- Identify botnet panels with Ensembled Decision Trees☆18Updated 8 years ago
- Metadata Inspection Database Alerting System☆42Updated 11 years ago
- A Volatility plugin for finding sqlite database rows☆22Updated 5 years ago
- onigiri - remote malware triage script☆25Updated 9 years ago
- misc scripts☆36Updated 6 years ago
- Python interface to the CRITs API☆22Updated 7 years ago
- Some dfir stuff☆31Updated 3 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆42Updated 4 years ago
- An active domain name query tool to help keep track of domain name movements...☆15Updated 3 years ago
- Email Abuse - A Versatile Software for Email review, analysis and reporting☆21Updated 9 years ago
- Server for receiving autorun data from the clients☆13Updated 7 years ago
- Graph-theoretical investigation of a corpus of malware obtained from the web☆21Updated 10 years ago
- Yara syntax highlighting☆25Updated 3 years ago
- Cli interface to threatcrowd.org☆19Updated 7 years ago
- Recurse through a registry, identifying values with large data -- a registry malware hunter☆44Updated 8 years ago
- Automation for VirusTotal☆31Updated 8 years ago