This is your work, valued

UK

Mark Woan

Elite
@woanware

DFIR, threat hunting, application security, mainly golang, C# and maybe a little python Mastodon: @woany@infosec.exchange

LogViewer. LogViewer for viewing and searching large text files...

423

usbdeviceforensics. Python script for extracting USB information from Windows registry hives

130

LogViewer2. Application for viewing/searching large text/log files (WPF port of the original LogViewer)

60

autorunner. Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing

55

ForensicUserInfo. Extracts Windows user info including the password hashes

40

wmi-parser. Parses the WMI object database....looking for persistence

35

lookuper. Looks stuff up (MD5, SHA256, IP, Domains, URL's, strings e.g. mutexes)...

35

etw-event-dumper. C#

33

woanware.github.io. HTML

33

application-restriction-bypasses. A set of compiled application restriction bypasses

30

TargetAnalyser. Tool for analysts to perform simultaneous lookups (IP, Domain, URL, MD5) against multiple data sources

28

NetworkScanViewer. C#

23

JumpLister. C#

18

bgp-watcher. Prototype system to monitor BGP routes and alert when anomalies are identified

15

Win32Security. C#

14

SessionViewer. SessionViewer is a PCAP TCP session reconstructor with a UI to view the data flows, and export data

12

reg-entropy-scanner. Scans through registry hives outputting entropy values for key/values, dumps binary contents to files...we are looking for those "fileless" malwarez!

11

volatility-runner. volatility-runner is a command line application designed to speed up memory forensics using the volatility framework, primarily for instances where the user has multiple memory dumps to analyse.

10

log-file-decrufter. Go

9

win-catalog-dotnet. Managed library for accessing the Windows security catalog files

9

javaidx. C#

8

exefinder. C#

8

xor. C#

7

extract-web-domains. Tool to extract domains/IP's from files

6

filesender. Send files simply using Google Drive...it's a cross between https://github.com/schollz/croc and https://github.com/google/skicka

5

shimcacheparser. C#

5

EventLogParser. C#

5

atomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.

5

VtLookup. C#

4

shellify. This is a fork from the Shellify project hosted on sourceforge. It replaces my own LNK parser as it has more features!

4

RegRipperRunner. C#

4

tr3_tool_kit. Repository to store the tools for Corey Harrell's Tr3Secure Data Collection script

4

VirtualDesktopUtils. The best Windows virtual desktop utility application in the world, probably, maybe, not......but even so it's very useful

4

snorbert. Snort data viewer...

3

word-password-generator. Console application to generate word based passwords using Mnemonicodes

3

threatexpertchecker. C#

3

logsifter. C#

2

ooxml-checker. Go

2

csv2xlsx. C#

2

RiskIqSharp. C# library (.Net 6) to interact with the RiskIQ/PassiveTotal API

2

csv-value-counter. A rewrite in golang of my .Net csvvaluecounter tool. Basically it counts the number of a particular field in a text file or CSV file

2

csvvaluecounter. C#

1

HttpKit. C#

1

log-sifter. Performs normalised levenshtein distance calculations on log entries to reduce repeated data...

1