reuteras / dfirwsLinks
Do DFIR work in a Windows Sandbox
☆17Updated this week
Alternatives and similar repositories for dfirws
Users that are interested in dfirws are comparing it to the libraries listed below
Sorting:
- ☆53Updated last month
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆80Updated this week
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆55Updated 2 years ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆88Updated 8 months ago
- Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations☆97Updated last month
- An exercise to practice deobfuscating PowerShell Scripts.☆26Updated 2 years ago
- This script enhances endpoint logging telemetry for the purpose of advanced malware threat detection or for building detections or malwar…☆33Updated 6 months ago
- A C# based tool for analysing malicious OneNote documents☆116Updated 2 years ago
- http://moaistory.blogspot.com/2018/10/winsearchdbanalyzer.html☆124Updated last year
- Windows.EDB Browser☆58Updated 2 years ago
- A forensic open-source parser module for Autopsy that allows extracting the messages, comments, posts, contacts, calendar entries and rea…☆103Updated this week
- ☆19Updated 3 years ago
- Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE☆33Updated last year
- Evtx Log (xml) Browser☆55Updated 2 years ago
- A repo hosting the Markua content for the EZ Tools manuals hosted on Leanpub☆82Updated 2 months ago
- A list of RMMs designed to be used in automation to build alerts☆113Updated 6 months ago
- Initial triage of Windows Event logs☆102Updated last year
- Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indi…☆108Updated last year
- Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!☆47Updated last year
- Tools and scripts to deploy and manage OpenRelik instances☆15Updated 4 months ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆37Updated last year
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆113Updated 3 years ago
- The home of the SDDLMaker☆24Updated 8 months ago
- ☆23Updated last month
- A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. P…☆28Updated 2 years ago
- VTC - Velociraptor Timeline Creator☆18Updated last year
- FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), gene…☆89Updated last week
- Full of public notes and Utilities☆127Updated 8 months ago
- ☆202Updated 11 months ago
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆109Updated last month