Found 472 repositories(showing 30)
Yamato-Security
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
bluecapesecurity
Practical Windows Forensics Training
MarkBaggett
A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.
cryps1s
DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.
DFIR-ORC
Forensics artefact collection tool for systems running Microsoft Windows
0xrajneesh
Hands-on projects for beginners to learn and practice Windows forensics and essential cybersecurity skills
digitalsleuth
Windows Forensics Environment Builder
botherder
pcqf (PC Quick Forensics) helps quickly gathering forensic evidence from Windows, Mac, and Linux systems, in order to identify potential traces of compromise.
trolldbois
Process heap analysis framework - Windows/Linux - record type inference and forensics
Yamato-Security
WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Response (DFIR), providing visibility into system activity and security events.
darkquasar
A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics
Yamato-Security
RustyBlue is a rust implementation of DeepblueCLI, a forensics log analyzer for finding evidence of compromise from windows event logs.
thereisnotime
Windows anti-forensics USB monitoring tool.
Ghassan-elsman
Windows forensics Engine
davidhowell-tx
PowerShell scripts for Hard Drive forensics and parsing Windows Artifacts
log2timeline
Digital Forensics Windows Registry (dfWinReg)
yasser-alghamdi
Winterfell is a group of windows batch scripts to collect Windows forensics data and perform efficient, and fast incident response and threat hunting activities.
harris21
Automation Forensics Tool for Windows
brazilianscriptguy
Enterprise PowerShell & VBScript suite for Active Directory automation, ITSM-aligned provisioning, security hardening, and digital forensics - built for Windows Server and workstation environments by a Senior IAM Analyst with a focus on accuracy, scalability, and compliance.
mnemonic-no
Volatility memory forensics plugin for extracting Windows DNS Cache
darkoperator
Collection of single use scripts I worte for windows forensics
bluedangerforyou
This tool will allow Forensic Investigators retrieve saved data from Google Chrome such as saved passwords and usernames, searches, history, and autofill data
MikeHorn-git
Hardened your Windows OS against forensics analysis
digitalsleuth
Windows Forensics Salt States
brootware
Easy automated vagrant provisioning of Windows 10 with flarevm tools installed for Digital Forensics and Malware Analysis Lab.
yarox24
Fix acquired .evt - Windows Event Log files (Forensics)
vm32
Digital forensics image that was prepared to cover a full Windows Forensics
DefinetlyNotAI
A powerful tool designed to harvest and collect a wide range of windows system data for forensics.
capelabs
A lightweight, extensible forensic tool that leverages eBPF to collect real-time system events on Windows for Digital Forensics and Incident Response.
Ankits39229
A professional hybrid digital forensics tool consisting of a high-performance Rust CLI engine and an intuitive Electron GUI for rapid Windows system analysis.