This is your work, valued
DFIR, threat hunting, application security, mainly golang, C# and maybe a little python Mastodon: @woany@infosec.exchange
LogViewer. LogViewer for viewing and searching large text files...
423usbdeviceforensics. Python script for extracting USB information from Windows registry hives
130LogViewer2. Application for viewing/searching large text/log files (WPF port of the original LogViewer)
60autorunner. Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing
55ForensicUserInfo. Extracts Windows user info including the password hashes
40wmi-parser. Parses the WMI object database....looking for persistence
35lookuper. Looks stuff up (MD5, SHA256, IP, Domains, URL's, strings e.g. mutexes)...
35etw-event-dumper. C#
33woanware.github.io. HTML
33application-restriction-bypasses. A set of compiled application restriction bypasses
30TargetAnalyser. Tool for analysts to perform simultaneous lookups (IP, Domain, URL, MD5) against multiple data sources
28NetworkScanViewer. C#
23JumpLister. C#
18bgp-watcher. Prototype system to monitor BGP routes and alert when anomalies are identified
15Win32Security. C#
14SessionViewer. SessionViewer is a PCAP TCP session reconstructor with a UI to view the data flows, and export data
12reg-entropy-scanner. Scans through registry hives outputting entropy values for key/values, dumps binary contents to files...we are looking for those "fileless" malwarez!
11volatility-runner. volatility-runner is a command line application designed to speed up memory forensics using the volatility framework, primarily for instances where the user has multiple memory dumps to analyse.
10log-file-decrufter. Go
9win-catalog-dotnet. Managed library for accessing the Windows security catalog files
9javaidx. C#
8exefinder. C#
8xor. C#
7extract-web-domains. Tool to extract domains/IP's from files
6filesender. Send files simply using Google Drive...it's a cross between https://github.com/schollz/croc and https://github.com/google/skicka
5shimcacheparser. C#
5EventLogParser. C#
5atomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.
5VtLookup. C#
4shellify. This is a fork from the Shellify project hosted on sourceforge. It replaces my own LNK parser as it has more features!
4RegRipperRunner. C#
4tr3_tool_kit. Repository to store the tools for Corey Harrell's Tr3Secure Data Collection script
4VirtualDesktopUtils. The best Windows virtual desktop utility application in the world, probably, maybe, not......but even so it's very useful
4snorbert. Snort data viewer...
3word-password-generator. Console application to generate word based passwords using Mnemonicodes
3threatexpertchecker. C#
3logsifter. C#
2ooxml-checker. Go
2csv2xlsx. C#
2RiskIqSharp. C# library (.Net 6) to interact with the RiskIQ/PassiveTotal API
2csv-value-counter. A rewrite in golang of my .Net csvvaluecounter tool. Basically it counts the number of a particular field in a text file or CSV file
2csvvaluecounter. C#
1HttpKit. C#
1log-sifter. Performs normalised levenshtein distance calculations on log entries to reduce repeated data...
1