CTO for Internet Storm Center and Professor at @SANS-Technology-Institute Author of SEC573 Automating Information Security with AI and Python
srum-dump. A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.
760domain_stats. Python
229freq. This is a repository for freq.py and freq_server.py
224MarkBaggett. Python
196ese-analyst. This is a set of tools for doing forensics analysis on Microsoft ESE databases.
130werejugo. Identifies physical locations where a laptop has been based upon wireless profiles and wireless data recorded in event logs
104504lab. Distribution of the SANS SEC504 Windows Cheat Sheet Lab
82apiify. Wrap any binary into a cached webserver
63pyWars. The latest pyWars client for the SEC573 class
49GeoLocationNotebook. Jupyter Notebook
39reassembler. Scapy packet fragment reassembly engines
35domain_stats2. Python
14pxpowershell. Python
14sec573_book_indexer. A project maintained by all SEC573 alumni. Contribute and make it better!
9ssl_sidejacker. Uses Event Tracing to peek inside the SSL packets to show cookies and other encrypted data
7srum-dump3. srum-dump3
6ping_app. HTML
5butterfly. A web terminal based on websocket and tornado
4RLLM_POC_DEMO. This repo has a (not for production) example of using recursive LLM techniques
4logic_and_bases. A small lab exercise to practice your base conversions and logical operators
3example-python-actions. An example GitHub Action using Python Actions
2colab_python. Jupyter Notebook
2mintty. The Cygwin Terminal – terminal emulator for Cygwin, MSYS, and WSL
2dshield. DShield Raspberry Pi Sensor
2python-egnyte. Python client for the Egnyte Public API.
1406-demo-range. HCL
1