
FileWatchTower
FWT is a security analysis and file monitoring tool that utilizes Sysmon events.
digital-forensicsforensicshash-analysis+4
29

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Easy-to-use live forensics toolbox for Linux endpoints