-
evtx Public
Forked from EricZimmerman/evtxC# based evtx parser with lots of extras
C# MIT License UpdatedDec 20, 2024 -
RECmd Public
Forked from EricZimmerman/RECmdCommand line access to the Registry
Rebol MIT License UpdatedMar 29, 2024 -
KapeFiles Public
Forked from EricZimmerman/KapeFilesThis repository serves as a place for community created Targets and Modules for use with KAPE.
MIT License UpdatedMar 29, 2024 -
INDXRipper Public
Forked from harelsegev/INDXRipperCarve file metadata from NTFS index ($I30) attributes
Python MIT License UpdatedFeb 3, 2023 -
-
dissect-acquire Public
Compiled Windows binary of acquire from Fox-IT dissect project
-
-
Get-LateralMovement Public
This script will accept the mounted drive or full path to an evidence source and process relevant forensic artifacts for evidence of lateral movement.
PowerShell UpdatedFeb 14, 2022 -
Get-KapeModuleBinaries Public
Forked from mark-hallman/Get-KapeModuleBinariesParses KAPE module files and downloads binaries referenced by BinaryURL
PowerShell MIT License UpdatedApr 15, 2021 -
plaso_filters Public
Forked from mark-hallman/plaso_filtersScripts to facilitate filtering with Plaso
UpdatedMay 20, 2020 -
KAPE-Binary-Downloads Public
Script to download binary tools for KAPE modules
-
usbdeviceforensics Public
Forked from woanware/usbdeviceforensicsPython script for extracting USB information from Windows registry hives
-
-
-
-
sysmon-config Public
Forked from SwiftOnSecurity/sysmon-configSysmon configuration file template with default high-quality event tracing
UpdatedJan 12, 2019 -