This is your work, valued
Awesome-BEC. Repository of attack and defensive information for Business Email Compromise investigations
278detections. Shell
51googleURLParser. parser for Google search strings
404n6_stuff. Git for me to put all my forensics stuff
23block-parser. Parser for Windows PowerShell script block logs
15regripper_gui. GUI for regripper
11homespeak. Script for querying Google home devices
11iOS-Parsers. parsers for iOS forensic artefacts
8ParseiOSSpotify. Parsing the Recently Played file on the iOS Spotify app
5exfat_stuff. Exfat documentation and scripts
3MacForensics. A repo for the scripts and research regarding OS X Forensics
3Regripper-Plugins. Repo for my regripper plugins
3sqlite-to-json-python. Convert sqlite databases to JSON files
3OLE_Research. Repo for my research into jumplist tools
2SundayFunday. scripts written for HECFBlogs Sunday Funday challenges
2tool_downloader. Perl
2TheDefendersGuide. The Github project for The Defender's Guide by Luke Paine and Jonathan Johnson
2parse_tasks. PowerShell
1SQLECmd. C#
1evtx. C# based evtx parser with lots of extras
1randomaccess3.github.io. Github IO
1velociraptor-docs. Documentation site for Velociraptor
1entropy_plot. Python
1RMM-Catalogue.
1sigma. Main Sigma Rule Repository
1INDXRipper. Carve file metadata from NTFS index ($I30) attributes
1velociraptor-detections.
1LOLRMM. LotL RMM
1bmc-tools. RDP Bitmap Cache parser
1uac. UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
1randomaccess3. Homepage
1bulk_extractor. This is the development tree. Production downloads are at:
1DFIR_Ransomware_Project.
1KapeFiles. This repository serves as a place for community created Targets and Modules for use with KAPE.
1pykapetargetexec. Python runner for kape modules
1