DFIR @ Unit 42, Admin of the Digital Forensics Discord Server, USMC Veteran, Former LE.
DFIRArtifactMuseum. The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.
660DFIRMindMaps. A repository of DFIR-related Mind Maps geared towards the visual learners!
552VanillaWindowsReference. A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update. Use these CSVs to create your own known good hash sets!
202Awesome-KAPE. A curated list of KAPE-related resources
191DFIRRegex. A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.
108KAPE-EZToolsAncillaryUpdater. A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools
59DFIRPowerShellScripts. Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!
53VanillaWindowsRegistryHives. A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update.
52EventTranscript.db-Research. A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.
43DirectoryOpus-DFIRConfig. A config file that's curated for DFIR examiners with shortcuts to common Windows artifacts and settings enabled that help make your life easier with various file management tasks.
43Anti-Forensics-VHDX. A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. Please add a new issue if you have an idea for something to add.
27SANSGoldPaperResearch_FOR500_Rathbun. A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.
27SigHunter. A C# (.NET 6) tool to compare the file signature of files recursively and inform the user of matches and mismatches
18ForensicImageKAPEOutput. A repository of output using KAPE (!EZParser Module) for various publicly available forensic images!
17PCAParser. A PowerShell script that can be used to parse and convert to CSV the new Windows 11 artifacts found in C:\Windows\appcompat\pca
10EventLogMonitor. An updated fork of @AbdulRhmanAlfaifi's EventLogMonitor, which hooks into Window Event Logs and displays the new events as they are written to disk.
9RAMDumpExplorer. An updated fork of @bacanoicua's RAMDumpExplorer project. This is a program designed to analyze a dump of the RAM memory to search for potentially malicious files. The program scans the dump file for specific patterns and uses regular expressions to identify and extract the matched values
8Windows11Research. A brain dump for any Windows 11 research that I may conduct
7WMI-Explorer. An updated fork of @vinaypamnani's wmie2 project
6KapeFiles. This repository serves as a place for community created Targets and Modules for use with KAPE.
6ForensicsTools. A list of free and open forensics analysis tools and other resources
5xxUSBSentinel. An updated fork of @thereisnotime's xxUSBSentinel, a Windows anti-forensics USB monitoring tool.
5Regshot-Advanced. This is an updated fork of RegShot Advanced. The main point of this fork is to provide a compiled, signed binary for the most recent version.
5Sync-EZTools. A short, focused PowerShell script to automate ensuring that all instances of EZ Tools in a given path have updated ancillary files
5WinTools. A collection of free miscellaneous Windows tools
4XstReader. An updated fork of @dijji's XstReader, which is an open-source viewer for Microsoft Outlook’s .OST and .PST files, written entirely in C#
4BeaconHunter. An updated fork of @3lp4tr0n's BeaconHunter. Detect and respond to Cobalt Strike beacons using ETW
4WMI-Parser. An updated fork of @woanware's WMI-Parser project
4AndrewRathbun.
4ForensicMiner. A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.
3iOS_Photos.sqlite_Queries. iOS Photos.sqlite queries that may help with decoding data stored in Photos.sqlite. These queries are based on testing, research and some community published research. These queries were written to work for the Photos.sqlite database stored at: iOS: /private/var/mobile/media/PhotoData/Photos.Sqlite Mac OS: /Users//Pictures/PhotosLibrary.photoslibrary/database/Photos.sqlite
3USB-Explorer. A tool that reads data stored under USBSTOR key in the system registry hive, representing information about connected USB storage devices
3bmc-tools. An updated fork of RDP Bitmap Cache parser, with outstanding PRs merged
3iOS_Test-Device_Photos.sqlite_Examples. This repo will contain several iOS Photos.sqlite databases, both Local Photo Library (LPL) db’s and Shared with You Syndication Photo Library (SWY) db’s that can be used to test Photos.sqlite queries.
3DFIR-Triage-Collector. Rapid DFIR Triage Collection Tool For Windows, Mac and Linux
3WinSearchDBAnalyzer. An updated fork of @moaistory's WinSearchDBAnalyzer project
3Get-UsnJrnlInfo. A fork of @evild3ad's Get-UsnJrnlInfo PowerShell Script. Very minor changes for the purpose of a KAPE Module. Gathers information from an extracted $Max file
3GHOSTS. GHOSTS is a realistic user simulation framework for cyber simulation, training, and exercise
3KapeDocs. Documentation repository
3Bogus. :card_index: A simple fake data generator for C#, F#, and VB.NET. Based on and ported from the famed faker.js.
2mRemoteNG. mRemoteNG is the next generation of mRemote, open source, tabbed, multi-protocol, remote connections manager.
2Get-ZimmermanTools. Get all my software
2extractTxtFromDocx. Digital Forensics focused Word file analysis tool
2CSVFileDetailsExtractor. A simple tool to enumerate useful details from CSV files recursively from a provided folder path
2LikeNtfsWalker. ToyProject_Like NTFSwalker
2awesome-forensics. A curated list of awesome forensic analysis tools and resources
2BinReveal. An updated fork of @MTJailed's BinReveal project. This is a project for analyzing files to find signatures or hidden files in a file
2OffensiveCSharp. Collection of Offensive C# Tooling
2Seatbelt. An updated fork of @GhostPack's Seatbelt project, Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
2iTired. A FAT Root Directory interpreter
2SQLECmd. This repository serves as a place for community created SQLECmd Maps for use with SQLECmd.
2