• Stars
    star
    3
  • Rank 3,963,521 (Top 79 %)
  • Language
    Nix
  • Created 5 months ago
  • Updated 4 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Reproducible forensics environment, 100% of the time

More Repositories

1

ttddbg

Time Travel Debugging IDA plugin
C++
551
star
2

Winshark

A wireshark plugin to instrument ETW
Lua
527
star
3

Yagi

Yet Another Ghidra Integration for IDA
C++
480
star
4

Invoke-Bof

Load any Beacon Object File using Powershell!
PowerShell
245
star
5

comida

An IDA Plugin that help analyzing module that use COM
Python
198
star
6

regrippy

A modern Python-3-based alternative to RegRipper
Python
184
star
7

etl-parser

Event Trace Log file parser in pure Python
Python
132
star
8

yara-ttd

Use YARA rules on Time Travel Debugging traces
C
86
star
9

vbSparkle

VBScript & VBA source-to-source deobfuscator with partial-evaluation
C#
72
star
10

ntTraceControl

Powershell Event Tracing Toolbox
PowerShell
72
star
11

CVE-2024-4040

Scanner for CVE-2024-4040
Python
50
star
12

etwbreaker

An IDA plugin to deal with Event Tracing for Windows (ETW)
Python
49
star
13

minusone

Powershell Linter
Rust
46
star
14

PSTrace

Trace ScriptBlock execution for powershell v2
C
39
star
15

tree-sitter-powershell

Powershell grammar for tree-sitter
JavaScript
36
star
16

dnYara

A multi-platform .Net wrapper library for the native Yara library.
C#
35
star
17

timeliner

A rewrite of mactime, a bodyfile reader
Go
34
star
18

Splunk-ETW

A Splunk Technology Add-on to forward filtered ETW events.
C#
30
star
19

cacdec

The hidden mstsc recorder player
Python
28
star
20

ttd2mdmp

Extract data of TTD trace file to a minidump
C++
28
star
21

dirtypipe-ebpf_detection

An eBPF detection program for CVE-2022-0847
C
27
star
22

mispy

Another MISP module for Python
Python
17
star
23

mispgo

Golang library for MISP
Go
5
star
24

usnrs

USN Journal parsing software and library
Rust
5
star
25

bodyfile

A bodyfile parsing library
Go
3
star
26

skyblue.team

Our website
HTML
1
star