
EnableWindowsLogSettings
Documentation and scripts to properly enable Windows event logs.

Documentation and scripts to properly enable Windows event logs.

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Read, understand and silence the Windows GDID device identifier (the ID that tracked a hacker through a VPN). Verified on a real Win11 VM. Honest: it…

A centralized and enhanced memory analysis platform

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

❤️ Free batch image & video geolocation digital forensics tool. Automatically extract EXIF data, visualize GPS coordinates on maps, and reconstruct…

Blue Team detection lab created with Terraform and Ansible in Azure.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…