Repository navigation

#

forensics-investigations

A suite of Tools to aid Incidence Response and Live Forensics for - Windows (Powershell) | Linux (Bash) | MacOS (Shell)

JavaScript
568
7 个月前

Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!

338
8 个月前

Imago is a python tool that extract digital evidences from images.

Python
256
3 年前

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to extract juicy information such as LAPS passwords or any sensitive information on the screen. Blue Team member can reconstruct PNG files to see what an attacker did on a compromised host. It is extremely useful for a forensics team to extract timestamps after an attack on a host to collect evidences and perform further analysis.

Python
215
7 年前

Windows Forensics Environment Builder

C#
132
3 个月前

Analyse a forensic target (such as a directory) to find and report files found and not found from CIRCL hashlookup public service - https://circl.lu/services/hashlookup/

Python
126
2 年前

Enhanced version of dd for forensics and security

C
101
4 个月前

PowerShell script designed to help Incident Responders collect forensic evidence from local and remote Windows devices.

PowerShell
101
8 个月前

Hardware arduino based mouse emulator, preventing screen saver locking (eg. during forensic investigation)

C++
91
7 年前

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV. Threats and data can be probed harnessing the power and syntax of SQL.

C#
81
1 年前

FTK Imager a Forensics Tools For MAC OS X

68
7 年前