-
-
dynmx Public
Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!
-
Kuiper Public
Forked from DFIRKuiper/KuiperDigital Forensics Investigation Platform
-
untitledgoosetool Public
Forked from cisagov/untitledgoosetoolUntitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to run a full investigation against a customer’s Azur…
Python Creative Commons Zero v1.0 Universal UpdatedApr 20, 2023 -
TCERT-Cumulonimbus-UAL_Extractor Public
Forked from tesorion/TCERT-Cumulonimbus-UAL_ExtractorCumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a Microsoft 365 environment.
PowerShell GNU General Public License v2.0 UpdatedApr 13, 2023 -
master-thesis Public
Master Thesis in Digital Forensics "Signature-Based Detection of Behavioural Malware Features with Windows API Calls"
-
velociraptor Public
Forked from Velocidex/velociraptorDigging Deeper....
Go Other UpdatedMar 9, 2022 -
capa-rules Public
Forked from mandiant/capa-rulesStandard collection of rules for capa: the tool for enumerating the capabilities of programs
Apache License 2.0 UpdatedJan 28, 2021 -