Repository navigation

#

digitalforensics

Collection of Event ID ressources useful for Digital Forensics and Incident Response

612
10 个月前

A repository of DFIR-related Mind Maps geared towards the visual learners!

520
3 年前

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

C++
255
2 年前

A curated list of KAPE-related resources

166
1 个月前

(Sometimes partial) Python re-implementations of the technologies involved in reading various data sources in Chrome-esque applications.

Python
166
3 个月前

Digital forensic analysis tool that provides a user-friendly interface for investigating disk images.

Python
164
20 天前

A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.

94
2 年前

A repo hosting the Markua content for the EZ Tools manuals hosted on Leanpub

Ruby
70
2 年前

A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts

60
5 个月前

A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools

PowerShell
55
3 个月前

Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!

PowerShell
45
7 个月前

A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update.

45
2 年前

A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.

39
3 年前

A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. Please add a new issue if you have an idea for something to add.

HTML
26
2 年前

Cryptocurrency Triage Tool - Identify multiple cryptocurrency addresses and transactions from various wallet applications!

Python
17
3 个月前

A repository of output using KAPE (!EZParser Module) for various publicly available forensic images!

16
8 个月前