Topic: "forensics"
ANSSI-FR/ADTimeline
Timeline of Active Directory changes with replication metadata
Language: PowerShell - Size: 1020 KB - Last synced at: about 22 hours ago - Pushed at: about 2 months ago - Stars: 499 - Forks: 63

ANSSI-FR/DFIR-O365RC
PowerShell module for Office 365 and Azure log collection
Language: PowerShell - Size: 172 KB - Last synced at: about 22 hours ago - Pushed at: 2 months ago - Stars: 266 - Forks: 31

ANSSI-FR/DFIR4vSphere
Powershell module for VMWare vSphere forensics
Language: PowerShell - Size: 113 KB - Last synced at: about 22 hours ago - Pushed at: 6 months ago - Stars: 150 - Forks: 18

ANSSI-FR/bootcode_parser
A boot record parser that identifies known good signatures for MBR, VBR and IPL.
Language: Python - Size: 1.26 MB - Last synced at: about 22 hours ago - Pushed at: 3 months ago - Stars: 98 - Forks: 23

ANSSI-FR/bits_parser
Extract BITS jobs from QMGR queue and store them as CSV records
Language: Python - Size: 18.6 KB - Last synced at: about 22 hours ago - Pushed at: 3 months ago - Stars: 75 - Forks: 6

ANSSI-FR/DECODE
Malware detection tool for Windows PE files based on DFIR ORC data
Language: Python - Size: 13.4 MB - Last synced at: about 22 hours ago - Pushed at: 9 days ago - Stars: 8 - Forks: 0
