reuteras / dfirwsLinks
Do DFIR work in a Windows Sandbox
☆16Updated 3 weeks ago
Alternatives and similar repositories for dfirws
Users that are interested in dfirws are comparing it to the libraries listed below
Sorting:
- Windows.EDB Browser☆57Updated 2 years ago
- ☆53Updated 3 weeks ago
- An exercise to practice deobfuscating PowerShell Scripts.☆26Updated 2 years ago
- This script enhances endpoint logging telemetry for the purpose of advanced malware threat detection or for building detections or malwar…☆33Updated 5 months ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆54Updated 2 years ago
- ☆204Updated 10 months ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆37Updated last year
- Recycle bin artifact parser☆52Updated 7 months ago
- A repo hosting the Markua content for the EZ Tools manuals hosted on Leanpub☆80Updated last month
- A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.☆37Updated 2 weeks ago
- Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations☆95Updated last month
- Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE☆33Updated last year
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆80Updated 4 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆88Updated 7 months ago
- ☆48Updated 8 months ago
- http://moaistory.blogspot.com/2018/10/winsearchdbanalyzer.html☆125Updated last year
- Venture: Cross-Platform GUI tool for parsing and analyzing Windows event logs☆91Updated 7 months ago
- A C# based tool for analysing malicious OneNote documents☆116Updated 2 years ago
- A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. P…☆28Updated 2 years ago
- A list of RMMs designed to be used in automation to build alerts☆112Updated 5 months ago
- Forensic tool for acquisition, triage and analysis of remote block devices via iSCSI protocol.☆42Updated 10 months ago
- Evtx Log (xml) Browser☆56Updated 2 years ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆62Updated 9 months ago
- ☆68Updated last month
- Tools and scripts to deploy and manage OpenRelik instances☆15Updated 3 months ago
- Command line access to the Registry☆155Updated 2 weeks ago
- PS-TrustedDocuments: PowerShell script to handle information on trusted documents for Microsoft Office☆35Updated 2 years ago
- Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or event…☆78Updated 4 years ago
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆110Updated last month
- ☆43Updated 4 years ago