Skip to content
View AndrewRathbun's full-sized avatar
🏠
Working from home
🏠
Working from home

Sponsoring

@EricZimmerman

Highlights

  • Pro

Organizations

@Digital-Forensics-Discord-Server

Block or report AndrewRathbun

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

🚀 My projects

A list of projects I've started and/or actively maintain
30 repositories

A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. Please add a new issue if you have an idea for something to a…

HTML 25 4 Updated Jan 2, 2023

A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.

39 3 Updated Jul 18, 2022

A config file that's curated for DFIR examiners with shortcuts to common Windows artifacts and settings enabled that help make your life easier with various file management tasks.

29 3 Updated Sep 19, 2024

A repository of output using KAPE (!EZParser Module) for various publicly available forensic images!

14 1 Updated Aug 31, 2024

A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.

84 10 Updated Nov 23, 2022

Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!

PowerShell 44 15 Updated Sep 26, 2024

Event Tracing For Windows (ETW) Resources

Python 349 68 Updated Oct 3, 2024

A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update. Use these CSVs t…

146 17 Updated Oct 3, 2024

A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of every Windows OS version to compare and see what's been added w…

43 5 Updated Apr 17, 2023

A curated list of KAPE-related resources

157 15 Updated Apr 29, 2024

A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools

PowerShell 53 5 Updated Sep 4, 2023

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifa…

HTML 555 46 Updated Nov 13, 2024

Documentation repository

HTML 43 4 Updated Aug 30, 2024

This repository serves as a place for community created Targets and Modules for use with KAPE.

658 193 Updated Nov 14, 2024

C# based evtx parser with lots of extras

C# 282 59 Updated Sep 5, 2024
C# 47 20 Updated Oct 30, 2024

Registry Explorer bookmark definitions

41 14 Updated Dec 11, 2022

Command line access to the Registry

Rebol 132 31 Updated Nov 3, 2024

Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/tag column, layout support, searching, etc.)

C# 22 6 Updated Nov 5, 2024

A repository of DFIR-related Mind Maps geared towards the visual learners!

514 67 Updated Sep 2, 2022

The official repo for a project involving a crowdsourced DFIR book. The main purpose of this book is to give anyone interested an opportunity to write a chapter of a book to get their name out ther…

Ruby 194 22 Updated Apr 29, 2024

Resources provided by the community that can serve to be useful for Law Enforcement worldwide

98 30 Updated Jul 25, 2024

A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.

HTML 25 4 Updated Jul 27, 2022

A repo hosting the Markua content for the EZ Tools manuals hosted on Leanpub

Ruby 64 5 Updated Aug 21, 2023

A PowerShell script that can be used to parse and convert to CSV the new Windows 11 artifacts found in C:\Windows\appcompat\pca

PowerShell 10 1 Updated Jul 3, 2023

A command-line application to extract (recursively, if needed) IDv3 metadata from audio files

C# 1 Updated May 18, 2024

A C# (.NET 6) tool to compare the file signature of files recursively and inform the user of matches and mismatches

C# 15 4 Updated Nov 19, 2024

A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts

51 6 Updated Nov 14, 2024

A simple tool to enumerate useful details from CSV files recursively from a provided folder path

C# 2 1 Updated May 20, 2024

A simple program to merge CSV files together.

C# 1 Updated May 20, 2024