davehull
Work Accounts: https://github.com/davehull-wiz https://github.com/davehull-rc
Various and sundryI am from enternetz
Pinned Repositories
autorunalyzer
A Python script for performing analysis of the output from Microsoft's Sysinternals Autoruns.
body-outliers
A Python script for finding outliers in fls bodyfiles (see The Sleuth Kit) based on given metadata elements like metadata address, atime, ctime, crtime and mtime.
Get-StakRank
A Powershell script for frequency analysis of separated values data files.
Kansa
A Powershell incident response framework
Mal-Seine
Why hunt when you can seine?
MCC
Tracking my work through the Matasano Crypto Challenges
PowerForensics
PowerShell - Live disk forensics platform
VirusTotalShell
A fork of David B Heise's VirusTotal Powershell Module
davehull's Repositories
davehull/Mal-Seine
Why hunt when you can seine?
davehull/Get-StakRank
A Powershell script for frequency analysis of separated values data files.
davehull/Get-WebFile
Powershell script based on Boe Prox's Get-WebPage.ps1, but this one pulls down a specific file
davehull/PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework
davehull/PSProfile
A new repo to contain my psprofile
davehull/CimSweep
CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.
davehull/PSReflect
Easily define in-memory enums, structs, and Win32 functions in PowerShell
davehull/ACE
Automated, Collection, and Enrichment Platform
davehull/Add-Header
Utility script for adding a header to a data file
davehull/Demos
Various demos
davehull/Empire
Empire is a PowerShell and Python post-exploitation agent.
davehull/Get-Fields
Returns the field names from a separated values file, assuming the first line contains a header.
davehull/krabsetw
KrabsETW provides a modern C++ wrapper around the low-level ETW trace consumption functions.
davehull/Loki
Loki - Simple IOC and Incident Response Scanner
davehull/Pester
Powershell BDD style testing framework
davehull/PowerShellMethodAuditor
PowerShellMethodAuditor listens to the PowerShell ETW provider and logs PowerShell method invocations.
davehull/PSReflect-Functions
davehull/sandbox-attacksurface-analysis-tools
davehull/Update
davehull/analyzeMFT
davehull/awesome-threat-intelligence
A curated list of Awesome Threat Intelligence resources
davehull/davehull.github.io
davehull/dnSpy
.NET debugger and assembly editor
davehull/grr
davehull/ioc_writer
davehull/lpeworkshop
Windows / Linux Local Privilege Escalation Workshop
davehull/proxpy
davehull/pytan
Python Wrapper for Tanium's SOAP API
davehull/rekall
Rekall Memory Forensic Framework
davehull/ThreatHunter-Playbook
A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.