
AzureHunter
A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Collection of private Yara rules.

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Volatility plugin for extracts configuration data of known malware

This repository contains a list of new remediation scripts.

Collecting & Hunting for IOCs with gusto and style

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

Artifact collection tool for *nix systems

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Monitoring Registry and File Changes in Windows

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…