Pinned Repositories
Awesome-KAPE
A curated list of KAPE-related resources
Axiom-PowerShell
PowerShell scripts to aid investigators when utilizing O365 and Magnet Axiom.
CyberPipe
An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.
detonaRE
Capture. Detonate. Collect
Ginsu
Takes a larger image and 'chops' it down to <= 3GB zips to traverse Windows Defender for Endpoint
Mal-Hash
This script will generate hashes (MD5, SHA1, SHA256), submit the MD5 to Virus Total, and produce a text file with the results.
Presentations
Archive of presentations shared with the DFIR community.
PSHero
PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.
QuickPcap
A quick and easy PowerShell script to collect a packet trace with option to convert .etl to .pcap.
Magnet-RESPONSE-PowerShell
PowerShell scripts for running Magnet RESPONSE forensic collection tool in large enterprises.
dwmetz's Repositories
dwmetz/CyberPipe
An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.
dwmetz/QuickPcap
A quick and easy PowerShell script to collect a packet trace with option to convert .etl to .pcap.
dwmetz/PSHero
PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.
dwmetz/Mal-Hash
This script will generate hashes (MD5, SHA1, SHA256), submit the MD5 to Virus Total, and produce a text file with the results.
dwmetz/detonaRE
Capture. Detonate. Collect
dwmetz/Axiom-PowerShell
PowerShell scripts to aid investigators when utilizing O365 and Magnet Axiom.
dwmetz/Ginsu
Takes a larger image and 'chops' it down to <= 3GB zips to traverse Windows Defender for Endpoint
dwmetz/Presentations
Archive of presentations shared with the DFIR community.
dwmetz/Awesome-KAPE
A curated list of KAPE-related resources
dwmetz/Digital-Forensics-with-Kali-Linux
Digital Forensics with Kali Linux, published by Packt
dwmetz/incident-response-plan-template
A concise, directive, specific, flexible, and free incident response plan template
dwmetz/blue-jupyter
Jupyter Notebooks for the Blue Team
dwmetz/dwmetz.github.io
dwmetz/iLEAPP
iOS Logs, Events, And Plist Parser
dwmetz/reversinglabs-yara-rules
ReversingLabs YARA Rules
dwmetz/rules
Repository of yara rules
dwmetz/sift
SIFT
dwmetz/Toolbox
Miscellaneous scripts for public consumption that don't really need their own repository.
dwmetz/GCTI
dwmetz/KapeFiles
This repository serves as a place for community created Targets and Modules for use with KAPE.
dwmetz/Magnet-RESPONSE-PowerShell
PowerShell script for running Magnet RESPONSE forensic collection tool in large enterprises.
dwmetz/volatility3
Volatility 3.0 development