Pinned Repositories
grr
GRR Rapid Response: remote live forensics for incident response
memory-analysis
A Rekall interactive document for a Memory Analysis workshop/course.
rekall-agent-server
Rekall is an endpoint security solution.
velociraptor
Velociraptor hunts for evil...
eql2vql
Transform EQL detection rules to VQL artifacts
evtx-data
Publicly shareable windows event log message data
go-prefetch
A golang implementation of a prefetch parser.
oleparse
Golang parser for OLE files
vtypes
VTypes is a data driven binary parsing system in Go.
scudette's Repositories
scudette/velociraptor
Velociraptor hunts for evil...
scudette/awesome-incident-response
A curated list of tools for incident response
scudette/Audit
Collection of Audit and Compliance related VQL artifacts
scudette/http-logging-proxy
scudette/sandbox-attacksurface-analysis-tools
Set of tools to analyze Windows sandboxes for exposed attack surface.
scudette/WinPmem
The multi-platform memory acquisition tool.
scudette/aff4
The Advanced Forensic File Format. NOTE: This project has been split into C and Python projects and moved to https://github.com/aff4/pyaff4 and https://github.com/Velocidex/c-aff4
scudette/archiver
scudette/assert
A simple assertion library using Go generics
scudette/blackfriday
Blackfriday: a markdown processor for Go
scudette/DFIRArtifactMuseum
The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.
scudette/eql
scudette/eqllib
scudette/etw
Go library for ETW (Event Tracing for Windows) events processing
scudette/etw-providers-docs
Document ETW providers
scudette/evtx
Golang Parser for Microsoft Event Logs
scudette/EVTX-ATTACK-SAMPLES
Windows Events Samples
scudette/Extensible-Storage-Engine
scudette/fb-util-for-appx
Create .appx files.
scudette/go-ese
Go implementation of an Extensible Storage Engine parser
scudette/go-libaudit
go-libaudit is a library for communicating with the Linux Audit Framework.
scudette/impacket
Impacket is a collection of Python classes for working with network protocols.
scudette/pywintrace
ETW Python Library
scudette/restic
Fast, secure, efficient backup program
scudette/RustyUsn
USN to JSON
scudette/sigma-go
A Go implementation and parser for Sigma rules.
scudette/tccprofile
Creates a TCC profile for new Privacy Payloads in macOS Mojave
scudette/ttlcache
An in-memory string-interface{} map with various expiration options for golang
scudette/velociraptor-docs
Documentation site for Velociraptor
scudette/winreg-kb
Windows Registry Knowledge Base