This is your work, valued

dfirfpi

Elite
@dfirfpi

logico

dpapilab. Windows DPAPI laboratory

98

decwindbx. A sort of a toolkit to decrypt Dropbox Windows DBX files

32

lsadecryptxp. LSASS LsaEncryptMemory(..decrypt..) for NT 5.1 and 5.2

5

HackInBo. Unofficial Collection of Slides and Programs of HackInBo

4

wbin_installer. Personal scripts to setup dfir tools on fedora

3

mvtu. MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

3

decoder. "secrets" decoding for FRITZ!OS devices

3

PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF

2

Bad-Pdf. Steal Net-NTLM Hash using Bad-PDF

2

MemLabs. Educational, CTF-styled labs for individuals interested in Memory Forensics

2

security-apis. A collective list of public APIs for use in security. Contributions welcome

2

Pentest-Tools.

2

Hob0Rules. Password cracking rules for Hashcat based on statistics and industry patterns

2

munin. Online hash checker for Virustotal and other services

1

PrivescCheck. Privilege Escalation Enumeration Script for Windows

1

etl-parser-ng. Event Trace Log file parser in pure Python

1

WindowsRpcClients. This respository is a collection of C# class libraries which implement RPC clients for various versions of the Windows Operating System from 7 to Windows 10.

1

r0ak. r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems

1

EVTX-ATTACK-SAMPLES. Windows Events Attack Samples

1

Zircolite. A standalone SIGMA-based detection tool for EVTX.

1

win-exec-calc-shellcode. A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)

1