0.0.0.0/0

Jan

Expert
@jgru

DFIR & TI & REM

consult-org-roam. A bunch of convenience functions for operating org-roam with the help of consult

161

spamtrap-system. Collection of tools to build and run a distributed spamtrap system, consisting of IMAP and SMTP collectors and a backend that extracts attachments, potentially analyzes malware and reports results to MISP or ES.

14

vmi-gui-reconstruction. Proof-of-concept code to reconstruct the GUI of a Xen guest running Windows

14

ansible-forensic-workstation. An Ansible playbook to create a basic Debian-based workstation for forensic tasks.

8

org-roam-ui. A graphical frontend for exploring your org-roam Zettelkasten

5

org-roam-desktop. A dead-simple desktop facility for org-roam

5

xmpp-mitm. Python utility that decrypts TLS encrypted XMPP traffic by acting as an active MITM and looking for STARTTLS requests

5

onion-domain-harvester. Small python tool to harvest onion domains and store them in a SQLite DB. Onion domains are scraped from the hiddenwiki and several clear web webpages, which list onion-domains.

4

ansible-drakvuf. Ansible role to install the black-box binary analysis DRAKVUF

3

hashlab. Generates lists of hashes of known benign and common files from Vagrant boxes in an automated manner for the use of whitelisting in DFIR workflows.

2

libja3. WIP! - C-Library to compute JA3 TLS fingerprints

2

ansible-cuckoo-virtualbox. Ansible role to deploy a Cuckoo sandbox host, which uses VirtualBox VMs as machinery

2

ufed-geo2x. This is a simple utility to extract geolocation data from a .xml-report of Cellebrite's UFED Physical Analyzer.

2

mailworm. Utility to parse a bunch of e-mails in .msg/.eml-format, to extract the most relevant information (header fields, attachments and their metadata), to enrich those information and store it in a .sqlite file

2

dfir-smb-share. A Docker-based SMB Share for DFIR work, which offers strong integrity protection by utilizing a trusted timestamping service

1

toolkit-obfuscator. Collection of simple scripts to modifiy a live response toolkit

1

grus-ghidra-scripts. Just a collection of my Ghidra/scripts to aid malware reversing

1

stream-to-s3. Stream data from stdin into an S3-bucket

1

raw-converter. Implementation of a raw processing pipeline to process .cr2-Files. Additionally flat stitching of raw-files by preserving their raw nature is conducted. Bachelor's project from 2014

1

docker-snort3. Lua

1
20
Apply