Skip to content
View AndrewRathbun's full-sized avatar
🏠
Working from home
🏠
Working from home

Sponsoring

@EricZimmerman

Highlights

  • Pro

Organizations

@Digital-Forensics-Discord-Server

Block or report AndrewRathbun

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Forked/Updated DFIR Tools

A list of tools (mostly C#) that I've forked and updated dependencies, compiled/signed a binary, updated the README, and in some instances, improved the tool!
16 repositories

An updated fork of @ignacioj's WMIParserStr project

C# 1 Updated Dec 6, 2024

An updated fork of @vinaypamnani's wmie2 project

C# 3 2 Updated Dec 6, 2024

An updated fork of @woanware's WMI-Parser project

C# 4 Updated Nov 29, 2024

An updated fork of @moaistory's WinSearchDBAnalyzer project

C# 3 Updated Sep 12, 2023

An updated fork of @dijji's XstReader, which is an open-source viewer for Microsoft Outlook’s .OST and .PST files, written entirely in C#

C# 4 Updated Jul 5, 2023

An updated fork of @3lp4tr0n's BeaconHunter. Detect and respond to Cobalt Strike beacons using ETW

C# 4 2 Updated May 30, 2024

A collection of free miscellaneous Windows tools

C# 4 Updated Jul 16, 2023

An updated fork of DateDecoder originally by @jacobsoo.

C# 1 Updated Nov 13, 2024

An updated fork of @thereisnotime's xxUSBSentinel, a Windows anti-forensics USB monitoring tool.

C# 5 1 Updated Dec 6, 2024

An updated fork of @GhostPack's Seatbelt project, Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive securit…

C# 1 Updated Dec 9, 2024

This is an updated fork of RegShot Advanced. The main point of this fork is to provide a compiled, signed binary for the most recent version.

C 5 Updated Sep 12, 2023

An updated fork of @MTJailed's BinReveal project. This is a project for analyzing files to find signatures or hidden files in a file

C# 1 Updated Dec 6, 2024

An updated fork of @bacanoicua's RAMDumpExplorer project. This is a program designed to analyze a dump of the RAM memory to search for potentially malicious files. The program scans the dump file f…

C# 7 Updated Nov 29, 2024

A fork of @evild3ad's Get-UsnJrnlInfo PowerShell Script. Very minor changes for the purpose of a KAPE Module. Gathers information from an extracted $Max file

PowerShell 3 Updated Sep 4, 2023

An updated fork of @AbdulRhmanAlfaifi's EventLogMonitor, which hooks into Window Event Logs and displays the new events as they are written to disk.

C# 6 1 Updated Dec 9, 2024

An updated fork of RDP Bitmap Cache parser, with outstanding PRs merged

Python 3 Updated May 30, 2024