Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Threat-Remediation-Scripts — This repository contains a list of new remediation scripts. | Kitploit
Herramientas/GitHubGitHub/xephora/threat-remediation-scripts
Defensive ToolsPacket Sniffing & AnalysisPort ScanningInformation GatheringMalware AnalysisDigital ForensicsIncident ResponseLog Analysis
GitHub
xephora/threat-remediation-scripts

Threat-Remediation-Scripts

This repository contains a list of new remediation scripts.

Ver Repositorio
1903129hace 18h 48mRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

Introduction

Since 2021, I have developed a number of scripts to assist me with my investigations and remediation efforts. I figured, why not share them to the public, in hopes it helps you.

How do these scripts work?

The scripts I developed are intended to work with Crowdstrike Endpoint Detection and Response (EDR). Essentially cloud scripts to quickly remediate devices remotely with a single click of a button.

Why create these scripts?

The purpose of my scripts is to assist a SOC or Incident Response Analyst with their investigation. Some scripts assist with remediation of a particular unwanted software/adware. Other scripts assist with investigating a particular system by username to provide more visibility.

Table of content

Manual Cloud Scripts

  • WinInspect - WinInspect is a light-weight tool to assist an analyst with providing more visibility into a Windows system based on a target username.
  • MACInspect - MACInspect is a light-weight tool to assist an analyst with providing more visibility into a MAC system based on a target username.
  • LinInspect - LinInspect is a light-weight tool to assist an analyst with providing more visibility into a Linux system based on a target username.
  • EnumChromeExt - EnumChromeExt retrieves Chrome Extensions and automatically attempts to detect the name.
  • Win-PortScanner - Win-PortScanner is an extremely light port scanner.
  • ScanDll - ScanDll is tool to help search processes for a particular dynamic-link library.
  • ScanDllv2 - ScanDllv2 is a tool designed to search processes for a specific dynamic-link library using C#. It's much faster than ScanDll, but the output is written to a log file due to issues with standard output display on the CrowdStrike RTR UI.
  • RegScanner - An amazingly fast tool designed to search for a registry key or value using a unique keyword.
  • Win-DiskImage-Toolkit - A simple tool to quickly enumerate or unmount a disk image.
  • ScreenConnect-C2Extractor - ScreenConnect-C2Extractor retrieves the C2 from the user.config of ScreenConnect aka ConnectWise Client.
  • Win-PacketCapture - A guided script to generate a packet dump for analysis.
  • EvidenceCollection - This script collects common user document types—such as Word files, Excel spreadsheets, text files, PDFs, and emails—from a specified user’s Downloads, Documents, and Desktop directories. It automatically creates the C:\temp\SIRT directory (if it does not already exist) and copies all matching files into that location for centralized review, evidence preservation, or incident investigation. The file types, directories, and username can be customized to fit the needs of the case.
  • Win-DmpEventLogs - Win-DmpEventLogs is an extremely useful forensic tool that allows you to dump Windows Event Logs within a specified time range: 1 = last 24 hours, 7 = last week, 30 = last month, 0 = all events.. Basic rules have been implemented to assist in identification.
  • Win-EnumVsCodeExtension - This PowerShell script enumerates installed Visual Studio Code extensions for a specified user account by inspecting the VS Code extensions directories and parsing each extension’s package.json metadata file.
  • Win-datebased_filehunt - This PowerShell script uses embedded C# code to recursively search the C:\ drive for files that were modified on a specific date. It logs all matching files, including their full path, last modified timestamp, and file size, to a log file located at C:\Windows\Temp\hunter_log_results.log.
  • Win-TokenImpersonateExec.ps1 - This script enables analysts to execute commands within the security context of a specified user by leveraging the user's access token. Please use this script only when necessary. As it executes commands within a target user's security context, it should be reserved for situations where user-specific artifacts, settings, or data must be collected and cannot be obtained through standard administrative or SYSTEM-level access.
  • Win-EnumLockedFile - This script leverages the Windows Restart Manager API to identify processes that currently have a specified file open or locked.

Misc Scripts

  • jsonspection - JSONSpection is a utility designed to thoroughly inspect and enumerate JSON data structures. It helps you break down complex or nested JSON blobs, identify all key-value paths, and understand the overall schema and relationships within the data. This makes it useful for debugging APIs, analyzing logs, or preparing data for parsing and automation workflows.
  • lin-EnumDisk - lin-diskenum.py enumerates raw disk images such as .img, .dd, and .raw files on Linux. It creates a read-only loop device, detects partitions/filesystems, and saves enumeration results separately under the enum/ directory.
  • lin-jextract - lin-jextract automatically identifies EXT filesystems within a Linux disk image and extracts their filesystem journals for forensic analysis.
  • x3 Ephemeral File Explorer - x3 is a lightweight Linux utility designed to streamline analyst workflows by launching a graphical file manager in a context-aware way. It supports direct directory browsing, as well as isolated, temporary workspaces for one or more files.
Descargar herramienta