GitHub topics: forensics
ANSSI-FR/ADTimeline
Timeline of Active Directory changes with replication metadata
Language: PowerShell - Size: 1020 KB - Last synced at: 1 day ago - Pushed at: 7 months ago - Stars: 515 - Forks: 66

ANSSI-FR/DFIR-O365RC
PowerShell module for Office 365 and Azure log collection
Language: PowerShell - Size: 283 KB - Last synced at: 1 day ago - Pushed at: 26 days ago - Stars: 275 - Forks: 33

ANSSI-FR/bootcode_parser
A boot record parser that identifies known good signatures for MBR, VBR and IPL.
Language: Python - Size: 1.26 MB - Last synced at: 1 day ago - Pushed at: 8 months ago - Stars: 96 - Forks: 23

ANSSI-FR/DECODE
Malware detection tool for Windows PE files based on DFIR ORC data
Language: Python - Size: 13.3 MB - Last synced at: 1 day ago - Pushed at: about 1 month ago - Stars: 10 - Forks: 0

ANSSI-FR/DFIR4vSphere
Powershell module for VMWare vSphere forensics
Language: PowerShell - Size: 113 KB - Last synced at: 1 day ago - Pushed at: 11 months ago - Stars: 155 - Forks: 18

ANSSI-FR/bits_parser
Extract BITS jobs from QMGR queue and store them as CSV records
Language: Python - Size: 18.6 KB - Last synced at: 1 day ago - Pushed at: 8 months ago - Stars: 75 - Forks: 6
