shujianyang / btrForensics
Forensic Analysis Tool for Btrfs File System.
☆21Updated 6 years ago
Alternatives and similar repositories for btrForensics
Users that are interested in btrForensics are comparing it to the libraries listed below
Sorting:
- AFF4 Standard Documents☆28Updated 3 years ago
- The ContactDB project was initiated to cover the need for a tool to maintain contacts for CSIRT teams☆37Updated 3 years ago
- Virustotal Data to Timesketch☆17Updated 6 years ago
- Plugins for the Viper Framework☆14Updated 5 years ago
- Event Log Analysis Tools☆29Updated 8 years ago
- Windows registry samples☆23Updated 6 years ago
- Indicators of compromise relating to our report on APT10's targeting of global MSPs☆10Updated 7 years ago
- ☆15Updated 7 years ago
- Yara rules for detecting malware☆23Updated 8 months ago
- Command Line STDOUT Colorer☆29Updated 3 years ago
- Binaries for the log2timeline projects and dependencies☆39Updated 8 months ago
- Parse IE, FireFox, Chrome and Safari Cookies for Google Analytic values☆23Updated 8 years ago
- Endpoint monitoring stack.☆18Updated 9 years ago
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated 2 years ago
- A DFVFS Backed Forensic Viewer☆40Updated 5 years ago
- Exporting MISP event attributes to yara rules usable with Thor apt scanner☆24Updated 8 years ago
- Registry Miner☆14Updated 7 years ago
- A Volatility plugin for finding sqlite database rows☆22Updated 5 years ago
- A collection of Volatility Framework plugins.☆26Updated 11 years ago
- Carve files for MFT entries (eg. blkls output or memory dumps). Recovers filenames (long & short), timestamps ($STD & $FN) and data if re…☆21Updated 5 years ago
- Script that checks for available updates for the most commonly used Digital Forensics tools☆59Updated 4 years ago
- An NTFS journal parser☆82Updated 9 years ago
- Yara is awesome, but sometimes you need to manipulate the data streams you're scanning in different ways.☆97Updated 10 years ago
- Validates yara rules and tries to repair the broken ones.☆39Updated 4 years ago
- Attempt to replicate the functions of auto_rip by Corey Harrell in Python.☆13Updated 9 months ago
- A tool to generate log messages related to interfaces, neighbor cache (ARP,NDP), IP address, routing, FIB rules, traffic control.☆32Updated 7 months ago
- Digital Forensics Windows Registry (dfWinReg)☆51Updated 4 months ago
- A Python script for indexing (putting) FireEye alert data into Elasticsearch...and notifying you too.☆16Updated 6 years ago
- Windows Thingies in Python for live use.☆24Updated 6 years ago
- Yara Scanner For IMAP Feeds and saved Streams☆28Updated 5 years ago