Tokyo, Japan

Minoru Kobayashi

Advanced
@mnrkbys

macosac. Forensic Artifact Collection Tool for macOS

121

fjta. FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), generates timelines, and detects suspicious activities.

112

vss_carver. Carves and recreates VSS catalog and store from Windows disk image.

101

ma2tl. macOS forensic timeline generator using the analysis result DBs of mac_apt

95

norimaci. Norimaci is a simple and lightweight malware analysis sandbox for macOS

71

bgiparser. A parsing tool for backgrounditems.btm

54

DSStoreParser. macOS .DS_Store Parser

7

linimagemounter. LinImageMounter is a Python tool designed to simplify the process of mounting disk images on Linux systems.

6

libvmdk-Shift_JIS. Library and tools to access the VMware Virtual Disk (VMDK) format

3

mac_apt. macOS (& ios) Artifact Parsing Tool

3

cidre-vm. Software installation scripts for macOS systems that allows you to setup a Virtual Machine (VM) for reverse engineering macOS malware

2

libvshadow-vss_carver. Library and tools to access the Volume Shadow Snapshot (VSS) format

2

precompiled_libyal_libs. Pre-compiled libyal libraries

2

FSEventsParser. Parser for OSX/iOS FSEvents Logs

2

Mac_ISF. Volatility3 ISF for Mac Os memory forensic.

1

CrackMapExec. A swiss army knife for pentesting networks

1

lldbinit. A gdbinit clone for LLDB

1

objective-see_Malware. macOS Malware Collection

1

afro. File recovery for APFS

1

sqlite-dissect. DC3 SQLite Dissect

1

llios. Random stuff about lower level iOS

1

Hibr2Bin. Comae Hibernation File Decompressor

1

uac. UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.

1

LinuxMalwareSourceCode. This is a repository of the source code of various malware targeting the *nix (mostly Linux) operating systems.

1

Mirai-Source-Code. Leaked Mirai Source Code for Research/IoC Development Purposes

1

APT06202001. Applied Purple Teaming - Infrastructure, Threat Optics, and Continious Improvement - June 6, 2020

1

volatility-plugins. Plugins I've written for Volatility

1

LinuxForensics. Everything related to Linux Forensics

1

macOS_FE. Tools for macOS Forensic Bootable media

1

WindowsMalwareSourceCode. Collection of Source Code of Various Malware Targeting the Windows Platform

1

KnockKnock. Enumerate persistently installed software

1

macos_execute_from_memory. PoC of macho loading from memory

1

flare-ida. IDA Pro utilities from FLARE team

1

Malware-Analysis-Training. Retired beginner/intermediate malware analysis training materials from @pedramamini and @erocarrera.

1

trochilus. A Fast & free Windows remote administration tool.

1
35
Apply