Skip to content
View awfr's full-sized avatar

Block or report awfr

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Loki - Simple IOC and YARA Scanner

Python 3,735 623 Updated Jan 12, 2026

Mobile Revelator

Python 189 31 Updated Apr 6, 2022

Simple hunting script for suspicious M365 OAuth Apps

Python 323 31 Updated Sep 23, 2025

Parses USB connection artifacts from offline Registry hives

Python 107 17 Updated Feb 8, 2026

A curated list of iOS Forensics References, organized by folder with specific references (links to blog post, research paper, articles, and so on) for each interesting file

228 30 Updated Dec 1, 2023

MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

Python 12,238 1,193 Updated Mar 18, 2026

A feature-rich command-line audio/video downloader

Python 152,539 12,377 Updated Mar 21, 2026

Script to download and decrypt memories and MEO from Snapchat on IOS. Requires the keys for memories to be present in the keychain, as well as the MEO key to get the MEO content.

Python 15 3 Updated Oct 31, 2022

A Powershell incident response framework

PowerShell 1,641 280 Updated Nov 22, 2022

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP, IMAP, etc from a pcap file or from a live interface.

Python 2,444 451 Updated Mar 2, 2026

Returns Logs Events And Properties Parser

Python 125 43 Updated Dec 24, 2025

Script to download all your Snapchat memories

Python 674 99 Updated Nov 13, 2025

ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit …

Python 174 29 Updated Mar 2, 2026

The official repo for a project involving a crowdsourced DFIR book. The main purpose of this book is to give anyone interested an opportunity to write a chapter of a book to get their name out ther…

Ruby 219 23 Updated Dec 30, 2025

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

PowerShell 776 115 Updated Mar 3, 2026

The Business Email Compromise Guide sets out to describe 10 steps for performing a Business Email Compromise (BEC) investigation in an Office 365 environment. Each step is intended to guide the pro…

279 34 Updated Feb 2, 2021