thimbleweed / All-In-USBLinks
☆146Updated 11 years ago
Alternatives and similar repositories for All-In-USB
Users that are interested in All-In-USB are comparing it to the libraries listed below
Sorting:
- Parses amcache.hve files, but with a twist!☆141Updated 7 months ago
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆287Updated last year
- MAL-CL (Malicious Command-Line)☆316Updated 2 years ago
- Digital forensic acquisition tool for Windows based incident response.☆344Updated last year
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆193Updated last week
- Live forensic artifacts collector☆171Updated last year
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆248Updated 5 months ago
- Prefetch Explorer Command Line☆263Updated 7 months ago
- RegRipper3.0☆636Updated 8 months ago
- ☆84Updated last month
- Ransomware simulator written in Golang☆447Updated 3 years ago
- A Cobalt Strike Scanner that retrieves detected Team Server beacons into a JSON object☆169Updated 2 years ago
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆330Updated 3 months ago
- Run several volatility plugins at the same time☆114Updated 2 years ago
- #ThreatHunting #DFIR #Malware #Detection Mind Maps☆302Updated 3 years ago
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆105Updated 3 years ago
- The Windows Malware Analysis Reversing Core Tools☆96Updated 4 years ago
- Incident Response collection and processing scripts with automated reporting scripts☆308Updated last year
- Blue Team detection lab created with Terraform and Ansible in Azure.☆162Updated 9 months ago
- Lnk Explorer Command line edition!!☆320Updated 7 months ago
- ☆197Updated last year
- evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.☆155Updated 3 years ago
- Checks running processes, process metadata, Dlls loaded into your current process and the each DLLs metadata, common install directories,…☆269Updated last year
- A python script developed to process Windows memory images based on triage type.☆265Updated last year
- Sysmon EDR POC Build within Powershell to prove ability.☆227Updated 4 years ago
- Test the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-Cradle…☆308Updated 3 years ago
- This script is made to collect the most valiable artifacts for foreniscs or incident reponse investigation rather than imaging the whole …☆202Updated 4 years ago
- C# based evtx parser with lots of extras☆318Updated last week
- ☆160Updated last year
- This repo is a collection of Ransomware reports from vendors, researchers, etc.☆119Updated 2 years ago