reverseame / winesapLinks
Volatility plugin to search for all Autostart Extensibility Points (AESPs)
☆10Updated last year
Alternatives and similar repositories for winesap
Users that are interested in winesap are comparing it to the libraries listed below
Sorting:
- ☆14Updated last year
- Scripts to facilitate filtering with Plaso☆128Updated 5 years ago
- An advanced parser for INDX records☆29Updated 6 years ago
- Collection of scripts provided for public use☆38Updated last week
- This is a set of tools for doing forensics analysis on Microsoft ESE databases.☆127Updated 4 years ago
- ☆42Updated 5 years ago
- Understanding and analyzing carrier files workshop repo☆51Updated 6 years ago
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆118Updated 2 years ago
- A python script developed to process Windows memory images based on triage type.☆263Updated 2 years ago
- The home of the BriMor Labs rdpieces Perl script that tries to rebuild parsed RDP Bitmap Cache images☆89Updated 2 years ago
- Hunt malware with Volatility☆47Updated 6 months ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆78Updated 2 years ago
- Python client for DFIR-IRIS☆25Updated last year
- Random notes collected on the intertubes relating to DFIR☆35Updated 2 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆43Updated 3 years ago
- ☆92Updated 6 months ago
- A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhanc…☆59Updated 7 months ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆55Updated 2 years ago
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆189Updated 3 months ago
- A GeoIP lookup utility utilizing ipinfo.io services.☆93Updated 2 years ago
- Repository of public reference frameworks for the DFIR community.☆121Updated 2 years ago
- 2021 SANS DFIR Summit: Greppin' Logs☆20Updated 3 months ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆117Updated 2 years ago
- "Evolving AppCompat/AmCache data analysis beyond grep"☆209Updated 4 years ago
- Parses KAPE module files and downloads binaries referenced by BinaryURL☆18Updated 6 years ago
- A curated list of KAPE-related resources☆179Updated 9 months ago
- Documentation repository☆47Updated last year
- Collection of useful, up to date, Carbon Black Response Queries☆84Updated 5 years ago
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆22Updated 4 years ago
- Script to automate Linux live evidence collection☆28Updated 3 years ago