I am from enternetz

Dave Hull

Elite
@davehull

Work Accounts: https://github.com/davehull-wiz https://github.com/davehull-rc

Kansa. A Powershell incident response framework

1.7k

Mal-Seine. Why hunt when you can seine?

21

VirusTotalShell. A fork of David B Heise's VirusTotal Powershell Module

17

Get-StakRank. A Powershell script for frequency analysis of separated values data files.

17

autorunalyzer. A Python script for performing analysis of the output from Microsoft's Sysinternals Autoruns.

15

MCC. Tracking my work through the Matasano Crypto Challenges

9

PowerForensics. PowerShell - Live disk forensics platform

8

body-outliers. A Python script for finding outliers in fls bodyfiles (see The Sleuth Kit) based on given metadata elements like metadata address, atime, ctime, crtime and mtime.

5

body-meta-dist. A Python script that parses the contents of an fls bodyfile (see The Sleuth Kit) and outputs the distribution of the metadata element passed as an argument.

4

body-ugid-dist. A Python script that parses the contents of an fls bodyfile (see The Sleuth Kit) and outputs the distribution of u/gids per directory. This has been useful for finding malicious code that an attacker has placed on a Linux host while neglecting to change u/gids to match "normal" values for the given directory.

4

meta-outliers. A Python script that finds files with metadata addresses that are n standard deviations from the average metadata address of files on a per directory basis.

3

PSProfile. A new repo to contain my psprofile

3

Get-WebFile. Powershell script based on Boe Prox's Get-WebPage.ps1, but this one pulls down a specific file

3

Exif2GeoRSS. Takes GPS Exif metadata from image files (or whatever) and creates a GeoRSS file suitable for import into Bing Maps. See http://trustedsignal.blogspot.com/2012/02/plotting-photo-location-data-with-bing.html.

3

PowerSploit. PowerSploit - A PowerShell Post-Exploitation Framework

3

CimSweep. CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.

2

PSReflect. Easily define in-memory enums, structs, and Win32 functions in PowerShell

2

PowerShellArsenal. A PowerShell Module Dedicated to Reverse Engineering

2

pefile. pefile is a Python module to read and work with PE (Portable Executable) files

1

datascience. Curated list of Python resources for data science.

1

at-ps. Adversary Tactics - PowerShell Training

1

math-as-code. a cheat-sheet for mathematical notation in code form

1

Add-Header. Utility script for adding a header to a data file

1

Get-Fields. Returns the field names from a separated values file, assuming the first line contains a header.

1

metasploit-framework. Metasploit Framework

1
25
Apply