Skip to content
View kmahyyg's full-sized avatar
👋
ISeekU
👋
ISeekU

Organizations

@pb-go

Block or report kmahyyg

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

DFIR

eBPF, Windows ETW, SIEM, Acquisition
75 repositories

Command line tracing tool for Windows, based on ETW.

C# 674 53 Updated Jan 16, 2024

Linux Evidence Acquisition Framework

Python 113 15 Updated Sep 30, 2024

Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, Th…

Python 3,047 455 Updated Dec 13, 2024

Dump of organized knowledge on DFIR

Python 132 28 Updated Oct 4, 2021

E-Mail Header Analyzer

HTML 657 165 Updated Apr 11, 2023

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

Swift 247 16 Updated Aug 23, 2024

Rapidly Search and Hunt through Windows Forensic Artefacts

Rust 2,949 270 Updated Dec 28, 2024

MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR

PowerShell 557 60 Updated Nov 24, 2024

UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD…

Shell 832 127 Updated Dec 20, 2024

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifa…

HTML 565 46 Updated Nov 13, 2024

MemProcFS

C 3,259 401 Updated Dec 28, 2024

The FLARE team's open-source tool to identify capabilities in executable files.

Python 4,977 567 Updated Dec 30, 2024

Encyclopedia for Executables

PowerShell 421 47 Updated Nov 9, 2021

A sort of a toolkit to decrypt Dropbox Windows DBX files

C 30 5 Updated Apr 30, 2017

ZincSearch . A lightweight alternative to elasticsearch that requires minimal resources, written in Go.

Go 17,121 744 Updated Oct 25, 2024

A lightning-fast search API that fits effortlessly into your apps, websites, and workflow

Rust 48,491 1,903 Updated Dec 31, 2024
Python 91 21 Updated Jun 7, 2022

Aftermath is a free macOS IR framework

Swift 484 33 Updated Nov 25, 2024

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

Python 157 25 Updated Jun 25, 2021

Parses RecentFileCacheParser.bcf files

C# 25 10 Updated Sep 5, 2024

A wireshark plugin to instrument ETW

Lua 539 59 Updated Jan 28, 2022

NTFS Master File Table (MFT) parser for Go.

Go 43 9 Updated Aug 21, 2024

Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine

Shell 403 74 Updated Dec 7, 2024

OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat and <UserCid>.dat.previous file.

Python 187 20 Updated Nov 20, 2024

eBPF implementation that runs on top of Windows

C 2,980 241 Updated Dec 31, 2024

Collection of Event ID ressources useful for Digital Forensics and Incident Response

596 85 Updated Jun 19, 2024

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Python 2,781 450 Updated Jun 21, 2024

Open EDR public repository

C++ 2,315 455 Updated Jan 13, 2024
YARA 535 68 Updated Dec 4, 2023