GitHub topics: forensics
ANSSI-FR/DFIR4vSphere
Powershell module for VMWare vSphere forensics
Language: PowerShell - Size: 113 KB - Last synced at: 4 days ago - Pushed at: over 1 year ago - Stars: 169 - Forks: 18
ANSSI-FR/DECODE
Malware detection tool for Windows PE files based on DFIR ORC data
Language: Python - Size: 13.3 MB - Last synced at: 4 days ago - Pushed at: 8 days ago - Stars: 10 - Forks: 2
ANSSI-FR/ADTimeline
Timeline of Active Directory changes with replication metadata
Language: PowerShell - Size: 1020 KB - Last synced at: 4 days ago - Pushed at: 12 months ago - Stars: 520 - Forks: 65
ANSSI-FR/bits_parser
Extract BITS jobs from QMGR queue and store them as CSV records
Language: Python - Size: 18.6 KB - Last synced at: 4 days ago - Pushed at: about 1 year ago - Stars: 74 - Forks: 6
ANSSI-FR/bootcode_parser
A boot record parser that identifies known good signatures for MBR, VBR and IPL.
Language: Python - Size: 1.26 MB - Last synced at: 4 days ago - Pushed at: about 1 year ago - Stars: 96 - Forks: 23
ANSSI-FR/DFIR-O365RC
PowerShell module for Office 365 and Azure log collection
Language: PowerShell - Size: 283 KB - Last synced at: 4 days ago - Pushed at: 6 months ago - Stars: 279 - Forks: 35