Michigan

Andrew Rathbun

Elite
@AndrewRathbun

DFIR @ Unit 42, Admin of the Digital Forensics Discord Server, USMC Veteran, Former LE.

DFIRArtifactMuseum. The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.

660

DFIRMindMaps. A repository of DFIR-related Mind Maps geared towards the visual learners!

552

VanillaWindowsReference. A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update. Use these CSVs to create your own known good hash sets!

202

Awesome-KAPE. A curated list of KAPE-related resources

191

DFIRRegex. A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.

108

KAPE-EZToolsAncillaryUpdater. A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools

59

DFIRPowerShellScripts. Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!

53

VanillaWindowsRegistryHives. A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update.

52

EventTranscript.db-Research. A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.

43

DirectoryOpus-DFIRConfig. A config file that's curated for DFIR examiners with shortcuts to common Windows artifacts and settings enabled that help make your life easier with various file management tasks.

43

Anti-Forensics-VHDX. A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. Please add a new issue if you have an idea for something to add.

27

SANSGoldPaperResearch_FOR500_Rathbun. A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.

27

SigHunter. A C# (.NET 6) tool to compare the file signature of files recursively and inform the user of matches and mismatches

18

ForensicImageKAPEOutput. A repository of output using KAPE (!EZParser Module) for various publicly available forensic images!

17

PCAParser. A PowerShell script that can be used to parse and convert to CSV the new Windows 11 artifacts found in C:\Windows\appcompat\pca

10

EventLogMonitor. An updated fork of @AbdulRhmanAlfaifi's EventLogMonitor, which hooks into Window Event Logs and displays the new events as they are written to disk.

9

RAMDumpExplorer. An updated fork of @bacanoicua's RAMDumpExplorer project. This is a program designed to analyze a dump of the RAM memory to search for potentially malicious files. The program scans the dump file for specific patterns and uses regular expressions to identify and extract the matched values

8

Windows11Research. A brain dump for any Windows 11 research that I may conduct

7

WMI-Explorer. An updated fork of @vinaypamnani's wmie2 project

6

KapeFiles. This repository serves as a place for community created Targets and Modules for use with KAPE.

6

ForensicsTools. A list of free and open forensics analysis tools and other resources

5

xxUSBSentinel. An updated fork of @thereisnotime's xxUSBSentinel, a Windows anti-forensics USB monitoring tool.

5

Regshot-Advanced. This is an updated fork of RegShot Advanced. The main point of this fork is to provide a compiled, signed binary for the most recent version.

5

Sync-EZTools. A short, focused PowerShell script to automate ensuring that all instances of EZ Tools in a given path have updated ancillary files

5

WinTools. A collection of free miscellaneous Windows tools

4

XstReader. An updated fork of @dijji's XstReader, which is an open-source viewer for Microsoft Outlook’s .OST and .PST files, written entirely in C#

4

BeaconHunter. An updated fork of @3lp4tr0n's BeaconHunter. Detect and respond to Cobalt Strike beacons using ETW

4

WMI-Parser. An updated fork of @woanware's WMI-Parser project

4

AndrewRathbun.

4

ForensicMiner. A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

3

iOS_Photos.sqlite_Queries. iOS Photos.sqlite queries that may help with decoding data stored in Photos.sqlite. These queries are based on testing, research and some community published research. These queries were written to work for the Photos.sqlite database stored at: iOS: /private/var/mobile/media/PhotoData/Photos.Sqlite Mac OS: /Users//Pictures/PhotosLibrary.photoslibrary/database/Photos.sqlite

3

USB-Explorer. A tool that reads data stored under USBSTOR key in the system registry hive, representing information about connected USB storage devices

3

bmc-tools. An updated fork of RDP Bitmap Cache parser, with outstanding PRs merged

3

iOS_Test-Device_Photos.sqlite_Examples. This repo will contain several iOS Photos.sqlite databases, both Local Photo Library (LPL) db’s and Shared with You Syndication Photo Library (SWY) db’s that can be used to test Photos.sqlite queries.

3

DFIR-Triage-Collector. Rapid DFIR Triage Collection Tool For Windows, Mac and Linux

3

WinSearchDBAnalyzer. An updated fork of @moaistory's WinSearchDBAnalyzer project

3

Get-UsnJrnlInfo. A fork of @evild3ad's Get-UsnJrnlInfo PowerShell Script. Very minor changes for the purpose of a KAPE Module. Gathers information from an extracted $Max file

3

GHOSTS. GHOSTS is a realistic user simulation framework for cyber simulation, training, and exercise

3

KapeDocs. Documentation repository

3

Bogus. :card_index: A simple fake data generator for C#, F#, and VB.NET. Based on and ported from the famed faker.js.

2

mRemoteNG. mRemoteNG is the next generation of mRemote, open source, tabbed, multi-protocol, remote connections manager.

2

Get-ZimmermanTools. Get all my software

2

extractTxtFromDocx. Digital Forensics focused Word file analysis tool

2

CSVFileDetailsExtractor. A simple tool to enumerate useful details from CSV files recursively from a provided folder path

2

LikeNtfsWalker. ToyProject_Like NTFSwalker

2

awesome-forensics. A curated list of awesome forensic analysis tools and resources

2

BinReveal. An updated fork of @MTJailed's BinReveal project. This is a project for analyzing files to find signatures or hidden files in a file

2

OffensiveCSharp. Collection of Offensive C# Tooling

2

Seatbelt. An updated fork of @GhostPack's Seatbelt project, Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.

2

iTired. A FAT Root Directory interpreter

2

SQLECmd. This repository serves as a place for community created SQLECmd Maps for use with SQLECmd.

2
51
Apply