Scripts automating computer forensics for Windows and Linux
-
Updated
May 23, 2022 - PowerShell
Scripts automating computer forensics for Windows and Linux
Faster & Better Way to analyze the EML Files
Security incident response case studies demonstrating log analysis, threat hunting, and forensic investigation using Elastic Stack, TheHive, and MITRE ATT&CK
Resources for DFIR. And more.
Cortex-Analyzers Modified - SecTeam/CERT/SOC Security orchestration tools on steroids
AutoParser is a forensic tool for parsing offline registry hives.
A forensic command-line tool for deep analyzing PDF files
This script is designed to pull data from the carbon black cloud. One disadvantage of the CBC GUI is the inability to see the command line for each process in bulk. Instead, you need to click on each process individually. This spits out the command line so you can quickly spot evil.
Windows Artifact Parser
Este script recompilará una gran parte de la información que se suele obtener de un sistema Linux ante un peritaje o análisis forense. Además toda la información será firmada con SHA256.
Linux Forensic Collector, Quick & Thorough.
This tool monitors Velociraptor's syslog messages for specific actions performed by users within the Velociraptor DFIR platform. When certain patterns are detected, it sends detailed email notifications to designated recipients, providing enhanced visibility into user activities and potential security events.
AWMFA - Automated Windows Memory Forensics Analysis. Python automation framework for Volatility 2 that streamlines memory analysis. Features: automated plugin execution with threading, intelligent threat detection using 28+ heuristics, no deep Windows internals knowledge required, multi-format reports (TXT/HTML/PDF).
Confirm file type by matching the magic signature ("number").
Exif and metadata dumper/searcher. PDF,JPG,PNG,EXE and a lot more supported.
Create a timeline of files in a folder.
Mac PenTesting & Digital Forensics Collection
Ingest and query NIST NSRL Reference Data Sets in Elasticsearch with Python tools and libraries.
Sabonis, a Digital Forensics and Incident Response pivoting tool
Add a description, image, and links to the dfir-automation topic page so that developers can more easily learn about it.
To associate your repository with the dfir-automation topic, visit your repo's landing page and select "manage topics."