strontic / xcyclopedia
Encyclopedia for Executables
☆436Updated 3 years ago
Alternatives and similar repositories for xcyclopedia:
Users that are interested in xcyclopedia are comparing it to the libraries listed below
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆568Updated this week
- A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.☆372Updated 2 years ago
- C# based evtx parser with lots of extras☆290Updated last month
- Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.☆243Updated 2 years ago
- Repository of YARA rules made by Trellix ATR Team☆577Updated last year
- Sysmon EDR POC Build within Powershell to prove ability.☆221Updated 3 years ago
- ☆146Updated 9 months ago
- Event Tracing For Windows (ETW) Resources☆363Updated 5 months ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆704Updated last month
- The multi-platform memory acquisition tool.☆756Updated 3 months ago
- IOC from articles, tweets for archives☆313Updated last year
- Parses $MFT from NTFS file systems☆227Updated last week
- A repo containing tools developed by Carbon Black's Threat Research Team: Threat Analysis Unit☆233Updated 3 years ago
- Misc Threat Hunting Resources☆373Updated 2 years ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆577Updated 10 months ago
- PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monit…☆794Updated 2 months ago
- A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.☆610Updated 4 months ago
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆606Updated 8 months ago
- A wireshark plugin to instrument ETW☆551Updated 3 years ago
- A collection of red team and adversary emulation resources developed and released by MITRE.☆498Updated 3 years ago
- MAL-CL (Malicious Command-Line)☆310Updated 2 years ago
- Regipy is an os independent python library for parsing offline registry hives☆253Updated 3 months ago
- ☆130Updated last year
- RegRipper3.0☆581Updated 3 months ago
- PowerShell script for deobfuscating encoded PowerShell scripts☆424Updated 4 years ago
- Detection in the form of Yara, Snort and ClamAV signatures.☆220Updated 4 months ago
- ☆757Updated last year
- A python script developed to process Windows memory images based on triage type.☆260Updated last year
- Prefetch Explorer Command Line☆246Updated 2 months ago
- 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system☆281Updated last month