Pinned Repositories
credmgr
Securely manage privileged account credentials via Shamir secret sharing
DFIR
Digital Forensics and Incident Response
docker-forensics
Incident response environment
Empire
Empire is a pure PowerShell post-exploitation agent.
flare-wmi
go-audit
go-audit is an alternative to the auditd daemon that ships with many distros
grr
GRR Rapid Response: remote live forensics for incident response
osxcollector
A forensic evidence collection & analysis toolkit for OS X
rekall
Rekall Memory Forensic Framework
james-baud's Repositories
james-baud/DFIR
Digital Forensics and Incident Response
james-baud/osxcollector
A forensic evidence collection & analysis toolkit for OS X
james-baud/rekall
Rekall Memory Forensic Framework
james-baud/credmgr
Securely manage privileged account credentials via Shamir secret sharing
james-baud/docker-forensics
Incident response environment
james-baud/Empire
Empire is a pure PowerShell post-exploitation agent.
james-baud/flare-wmi
james-baud/go-audit
go-audit is an alternative to the auditd daemon that ships with many distros
james-baud/grr
GRR Rapid Response: remote live forensics for incident response
james-baud/gryffin
Gryffin is a large scale web security scanning platform
james-baud/HELK
The Hunting ELK
james-baud/Kansa
A Powershell incident response framework
james-baud/laikaboss
Laika BOSS: Object Scanning System
james-baud/metasploit-framework
Metasploit Framework
james-baud/osquery
SQL powered operating system instrumentation, monitoring, and analytics.
james-baud/plaso
Home of the super timeline
james-baud/PowerShellArsenal
A PowerShell Module Dedicated to Reverse Engineering
james-baud/protofuzz
Google Protocol Buffers message generator
james-baud/pupy
Pupy is a remote administration tool with an embeded Python interpreter, allowing its modules to load python packages from memory and transparently access remote python objects. The payload is a reflective DLL and leaves no trace on disk
james-baud/security_monkey
Security Monkey
james-baud/synfulknock
james-baud/WMIEventing
A PowerShell module to abstract the complexities of Permanent WMI Event Subscriptions
james-baud/WMIne