
whids
Windows EDR with Gene-based detection engine, real-time artifact collection, Sysmon integration, and REST API for managing endpoints, rules, and…

Windows EDR with Gene-based detection engine, real-time artifact collection, Sysmon integration, and REST API for managing endpoints, rules, and…

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Volatility plugin for extracts configuration data of known malware

Collecting & Hunting for IOCs with gusto and style

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

CredsHunter - Credential Hunting scripts for Windows and Linux OS

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

Artifact collection tool for *nix systems

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Automates incident response tasks via Carbon Black Response API: file/registry deletion, process killing, sensor isolation, binary collection, and…

Monitoring Registry and File Changes in Windows