Pinned Repositories
artifacts
Digital Forensics Artifact Repository
DetectionLab
Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices
dfir-toolset
Dump of organized knowledge on DFIR
evmount
The start of a be-all end-all for Linux mounting of VMDK's, EWF's, and dd's
LiME
LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures from Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it to produce memory captures that are more forensically sound than those of other tools designed for Linux memory acquisition.
logon_organizer
Pulls info from RDP, Terminal, Security, System (reboot) evtx's to show logons-logoffs
mint-csv-import
Import csv of transactions to mint using python 3
nsrlfilter
Startup script for handling multiple whitelists/blacklists for nsrllookup daemons
quick_linux_triage
marcurdy's Repositories
marcurdy/dfir-toolset
Dump of organized knowledge on DFIR
marcurdy/evmount
The start of a be-all end-all for Linux mounting of VMDK's, EWF's, and dd's
marcurdy/nsrlfilter
Startup script for handling multiple whitelists/blacklists for nsrllookup daemons
marcurdy/logon_organizer
Pulls info from RDP, Terminal, Security, System (reboot) evtx's to show logons-logoffs
marcurdy/mint-csv-import
Import csv of transactions to mint using python 3
marcurdy/quick_linux_triage
marcurdy/artifacts
Digital Forensics Artifact Repository
marcurdy/DetectionLab
Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices
marcurdy/LiME
LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures from Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it to produce memory captures that are more forensically sound than those of other tools designed for Linux memory acquisition.
marcurdy/osquery
SQL powered operating system instrumentation, monitoring, and analytics.
marcurdy/plaso
Super timeline all the things
marcurdy/profiles
Volatility profiles for Linux and Mac OS X
marcurdy/pySigma-backend-azure
Microsoft Sentinel backend for pySigma
marcurdy/pySigma-backend-carbonblack
marcurdy/RegRipper2.8
RegRipper version 2.8
marcurdy/sigma
Generic Signature Format for SIEM Systems
marcurdy/sof-elk
Configuration files for the SOF-ELK VM, used in SANS FOR572
marcurdy/splunk-spec-files
Splunk spec files version history