OMENScan
Some people write books to document and share what they learn. I write software.
The Internets
OMENScan's Stars
blueteamvillage/Project-Obsidian-DC31
blueteamvillage/Project-Obsidian-DC30
blueteamvillage/Project-Obsidian-DC29
WithSecureLabs/chainsaw
Rapidly Search and Hunt through Windows Forensic Artefacts
easttimor/aws-incident-response
dr-anoroc/rawccopy
Command line utility for copying files on NTFS using low level disk access
MarkBaggett/srum-dump
A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.
dylanaraps/pure-bash-bible
đź“– A collection of pure bash alternatives to external processes.
chenerlich/FCL
FCL (Fileless Command Lines) - Known command lines of fileless malicious executions
Lazza/RecuperaBit
A tool for forensic file system reconstruction.
google/timesketch
Collaborative forensic timeline analysis
booboule/FastResponder
Fork of the old Sekoialab Fast Responder
Yelp/osxcollector
A forensic evidence collection & analysis toolkit for OS X
Invoke-IR/PowerForensics
PowerForensics provides an all in one platform for live disk forensic analysis
google/grr
GRR Rapid Response: remote live forensics for incident response
AJMartel/IRTriage
Incident Response Triage - Windows Evidence Collection for Forensic Analysis
win-acme/win-acme
A simple ACME client for Windows (for use with Let's Encrypt et al.)
rshipp/awesome-malware-analysis
Defund the Police.
sleuthkit/sleuthkit
The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
sleuthkit/autopsy
Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.
Invoke-IR/ForensicPosters
volatilityfoundation/volatility
An advanced memory forensics framework
google/rekall
Rekall Memory Forensic Framework
jschicht/ExtractUsnJrnl
Tool to extract the $UsnJrnl from an NTFS volume
jschicht/RawCopy
Commandline low level file extractor for NTFS