
ir-rescue
A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.
digital-forensicsdisk-forensicsforensics+6
488

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…


FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…