Pinned Repositories
block-doh
RPZ Zone Files to Block DNS-over-HTTPS
checkpoint_client
A python client to interact with CheckPoint R80 API (https://sc1.checkpoint.com/documents/R80/APIs/#ws).
Chrome-Extension-Mapper
Simple script to map Chrome extension IDs to extension name and app store URL
crtsh_scanner
A tool to discover domains using crt.sh site (certificate transparency logs).
DLLPasswordFilterImplant
DLL Password Filter Implant with Exfiltration Capabilities
DNSrazzle
A pure python tool for finding and comparing typo-squatting, bytesqatting, phishing attacks and brand impersonation
evtx2json
A tool to convert Windows evtx files (Windows Event Log Files) into JSON format and log to Splunk (optional) using HTTP Event Collector.
splunk_hec_handler
A Python Logging Handler for Splunk HTTP Event Collector (HEC).
ts_webhook_alert
Splunk alert app for exporting indicators from Splunk to Anomali ThreatStream.
volatility_automation
A tool to automate memory dump processing using Volatility, including optional Splunk integration.
vavarachen's Repositories
vavarachen/evtx2json
A tool to convert Windows evtx files (Windows Event Log Files) into JSON format and log to Splunk (optional) using HTTP Event Collector.
vavarachen/crtsh_scanner
A tool to discover domains using crt.sh site (certificate transparency logs).
vavarachen/volatility_automation
A tool to automate memory dump processing using Volatility, including optional Splunk integration.
vavarachen/splunk_hec_handler
A Python Logging Handler for Splunk HTTP Event Collector (HEC).
vavarachen/block-doh
RPZ Zone Files to Block DNS-over-HTTPS
vavarachen/Chrome-Extension-Mapper
Simple script to map Chrome extension IDs to extension name and app store URL
vavarachen/checkpoint_client
A python client to interact with CheckPoint R80 API (https://sc1.checkpoint.com/documents/R80/APIs/#ws).
vavarachen/DLLPasswordFilterImplant
DLL Password Filter Implant with Exfiltration Capabilities
vavarachen/DNSrazzle
A pure python tool for finding and comparing typo-squatting, bytesqatting, phishing attacks and brand impersonation
vavarachen/ts_webhook_alert
Splunk alert app for exporting indicators from Splunk to Anomali ThreatStream.
vavarachen/flare-fakenet-ng
FakeNet-NG - Next Generation Dynamic Network Analysis Tool
vavarachen/python-whois
A python module for retrieving and parsing WHOIS data
vavarachen/site_compare
Proof of concept code for using the Structural Similarity Index Measurement (SSIM) for comparing 2 websites.
vavarachen/ThreatIngestor
Extract and aggregate threat intelligence.
vavarachen/threatstream-api