-
Unit 42
- Michigan
-
23:39
(UTC -05:00) - @bunsofwrath12
Highlights
- Pro
Forked/Updated DFIR Tools
An updated fork of @ignacioj's WMIParserStr project
An updated fork of @vinaypamnani's wmie2 project
An updated fork of @woanware's WMI-Parser project
An updated fork of @moaistory's WinSearchDBAnalyzer project
An updated fork of @dijji's XstReader, which is an open-source viewer for Microsoft Outlook’s .OST and .PST files, written entirely in C#
An updated fork of @3lp4tr0n's BeaconHunter. Detect and respond to Cobalt Strike beacons using ETW
An updated fork of DateDecoder originally by @jacobsoo.
An updated fork of @thereisnotime's xxUSBSentinel, a Windows anti-forensics USB monitoring tool.
An updated fork of @GhostPack's Seatbelt project, Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive securit…
This is an updated fork of RegShot Advanced. The main point of this fork is to provide a compiled, signed binary for the most recent version.
An updated fork of @MTJailed's BinReveal project. This is a project for analyzing files to find signatures or hidden files in a file
An updated fork of @bacanoicua's RAMDumpExplorer project. This is a program designed to analyze a dump of the RAM memory to search for potentially malicious files. The program scans the dump file f…
A fork of @evild3ad's Get-UsnJrnlInfo PowerShell Script. Very minor changes for the purpose of a KAPE Module. Gathers information from an extracted $Max file
An updated fork of @AbdulRhmanAlfaifi's EventLogMonitor, which hooks into Window Event Logs and displays the new events as they are written to disk.
An updated fork of RDP Bitmap Cache parser, with outstanding PRs merged