Pinned Repositories
4n6_misc
Miscellaneous Scripts
ArtifactExtractor
Extract common Windows artifacts from source images and VSCs
autoripy
Attempt to replicate the functions of auto_rip by Corey Harrell in Python.
BulkStrike
BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.
evtx2json
evtx2json extracts events of interest from event logs, dedups them, and exports them to json.
EVTXtract
EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
fbclicker
fbclicker is a set of scripts (currently only 1) to automate browsing activities on Facebook using Selenium.
GCP-IR-Notes
GCP IR Notes
macOSParsers
Scripts that parse macOS data objects
Windows-Event-Log-Messages
Retrieves the definitions of Windows Event Log messages embedded in Windows binaries and provides them in discoverable formats. #nsacyber
Silv3rHorn's Repositories
Silv3rHorn/ArtifactExtractor
Extract common Windows artifacts from source images and VSCs
Silv3rHorn/BulkStrike
BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.
Silv3rHorn/evtx2json
evtx2json extracts events of interest from event logs, dedups them, and exports them to json.
Silv3rHorn/4n6_misc
Miscellaneous Scripts
Silv3rHorn/autoripy
Attempt to replicate the functions of auto_rip by Corey Harrell in Python.
Silv3rHorn/macOSParsers
Scripts that parse macOS data objects
Silv3rHorn/GCP-IR-Notes
GCP IR Notes
Silv3rHorn/Windows-Event-Log-Messages
Retrieves the definitions of Windows Event Log messages embedded in Windows binaries and provides them in discoverable formats. #nsacyber
Silv3rHorn/EVTXtract
EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
Silv3rHorn/fbclicker
fbclicker is a set of scripts (currently only 1) to automate browsing activities on Facebook using Selenium.
Silv3rHorn/HFSMount
Scripts that mount and unmount HFS e01 images; based on SANS FOR518 method 1
Silv3rHorn/SeeMore
Google Chrome browser extension that expands FaceBook posts.
Silv3rHorn/Silv3rHorn
Silv3rHorn/Windows-Prefetch-Parser
Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files