
SwishDbgExt
Incident Response & Digital Forensics Debugging Extension

Incident Response & Digital Forensics Debugging Extension

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

Blue Team detection lab created with Terraform and Ansible in Azure.

Data from a BRAWL Automated Adversary Emulation Exercise

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Active Directory NTDS database parser that dumps records to JSON, supports object filtering, and decrypts encrypted columns using SYSTEM hive or…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

Native YARA scanner X-Tension for X-Ways Forensics, enabling in-snapshot file scanning with multi-threaded RVS support, report table output, and no…

A Repository to Track Anti-Forensic Techniques

Monitoring Registry and File Changes in Windows

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…

A swiss-knife MCP server for analysing PCAP files