LogonSessionAuditor. This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you select the EVTX file and specify a time for correlating login and logout events.
32regexplore. Regexplore is a Volatility plugin designed to mimic the functionality of the Registry Explorer plugins in EZsuite
18MISC. Shell
17Slack-Parser. Slack Parser is a script to parse slack database and extract user-data, chat history, workspace information
16Autopsy-Registry-Explorer. Autopsy Module to analyze Registry Hives
16Ingestors. A collection of PowerShell scripts designed to transform raw forensic data into formats suitable for analysis
12D-HATS. A framework for creating robust DFIR challenges. Features anti-forensic hardening (e.g., process hiding, MFT evasion) and automated testing to detect unintended solution paths.
11SnowCracker. Snowcracker used to crack Stegsnow passwords
9Hash-Extension-Bruter. Hash-Extender-Bruter is a tool in python to bruteforce Hash-extender length and send back cookie to website
7Artifast2Splunk. Artifast2Splunk is a collection of Splunk configuration files for ingesting, and parsing json output from artifast in Splunk.
2ludus-customization. Custom configurations for Ludus server to speed up deployments & debuggings,.
2