
macos-collector
macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR
digital-forensicsforensicsincident-response+2
52

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Tool to create hidden registry keys.

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.