
veeam-velociraptor
Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

A centralized and enhanced memory analysis platform

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Automated, Collection, and Enrichment Platform

Incident Response collection and processing scripts with automated reporting scripts

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Program for determining types of files for Windows, Linux and MacOS.

A repository of sysmon configuration modules

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Automation and Scaling of Digital Forensics Tools

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Defanged Indicator of Compromise (IOC) Extractor.

Volatility plugin for extracts configuration data of known malware