GitHub topics: forensics
ANSSI-FR/DFIR4vSphere
Powershell module for VMWare vSphere forensics
Language: PowerShell - Size: 113 KB - Last synced at: about 17 hours ago - Pushed at: about 1 year ago - Stars: 157 - Forks: 18
ANSSI-FR/ADTimeline
Timeline of Active Directory changes with replication metadata
Language: PowerShell - Size: 1020 KB - Last synced at: about 17 hours ago - Pushed at: 9 months ago - Stars: 520 - Forks: 66
ANSSI-FR/DFIR-O365RC
PowerShell module for Office 365 and Azure log collection
Language: PowerShell - Size: 283 KB - Last synced at: about 17 hours ago - Pushed at: 3 months ago - Stars: 276 - Forks: 35
ANSSI-FR/bootcode_parser
A boot record parser that identifies known good signatures for MBR, VBR and IPL.
Language: Python - Size: 1.26 MB - Last synced at: about 17 hours ago - Pushed at: 10 months ago - Stars: 96 - Forks: 23
ANSSI-FR/DECODE
Malware detection tool for Windows PE files based on DFIR ORC data
Language: Python - Size: 13.3 MB - Last synced at: about 17 hours ago - Pushed at: 3 months ago - Stars: 10 - Forks: 0
ANSSI-FR/bits_parser
Extract BITS jobs from QMGR queue and store them as CSV records
Language: Python - Size: 18.6 KB - Last synced at: about 17 hours ago - Pushed at: 10 months ago - Stars: 75 - Forks: 6