Andrew Rathbun (AndrewRathbun)

AndrewRathbun

Geek Repo

Company:@krollcyber

Location:Michigan

Home Page:https://aboutdfir.com/

Twitter:@bunsofwrath12

Github PK Tool:Github PK Tool


Organizations
Digital-Forensics-Discord-Server
ezoic increase your site revenue

Andrew Rathbun's repositories

DFIRMindMaps

A repository of DFIR-related Mind Maps geared towards the visual learners!

License:MITStargazers:369Issues:32Issues:0

DFIRArtifactMuseum

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.

Language:HTMLLicense:MITStargazers:130Issues:13Issues:4

Awesome-KAPE

A curated list of KAPE-related resources

License:MITStargazers:63Issues:7Issues:0

VanillaWindowsReference

A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update. Use these CSVs to create your own known good hash sets!

License:MITStargazers:39Issues:4Issues:0

DFIRRegex

A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.

License:MITStargazers:34Issues:3Issues:0

KAPE-EZToolsAncillaryUpdater

A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools

Language:PowerShellLicense:MITStargazers:25Issues:7Issues:7

VanillaWindowsRegistryHives

A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update.

DFIRPowerShellScripts

Various PowerShells scripts I've made to automate some of the boring stuff in my everyday DFIR journey!

Language:PowerShellLicense:MITStargazers:10Issues:1Issues:1

KapeFiles

This repository serves as a place for community created Targets and Modules for use with KAPE.

License:MITStargazers:4Issues:1Issues:0

KapeDocs

Documentation repository

Language:HTMLLicense:MITStargazers:2Issues:2Issues:0

EVTX-ETW-Resources

Event Tracing For Windows (ETW) Resources

License:MITStargazers:1Issues:0Issues:0

RECmd

Command line access to the Registry

Language:RebolLicense:MITStargazers:1Issues:1Issues:0

Slides

Misc Threat Hunting Resources

Stargazers:1Issues:0Issues:0

TLEFilePlugins

Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/tag column, layout support, searching, etc.)

Language:C#License:MITStargazers:1Issues:0Issues:0

APTSimulator

A toolset to make a system look as if it was the victim of an APT attack

Language:BatchfileLicense:MITStargazers:0Issues:0Issues:0

bstrings

A better strings utility!

Language:C#License:MITStargazers:0Issues:0Issues:0

CSIRT-Collect

PowerShell script to collect memory and (triage) disk forensics

Language:PowerShellLicense:MITStargazers:0Issues:0Issues:0

ericzimmerman.github.io

Software downloads

Language:HTMLLicense:MITStargazers:0Issues:0Issues:0

iOS_Photos.sqlite_Queries

iOS Photos.sqlite queries that may help with decoding data stored in Photos.sqlite. These queries are based on testing, research and some community published research. These queries were written to work for the Photos.sqlite database stored at: iOS: /private/var/mobile/media/PhotoData/Photos.Sqlite Mac OS: /Users//Pictures/PhotosLibrary.photoslibrary/database/Photos.sqlite

Stargazers:0Issues:0Issues:0

JLECmd

Automatic and Custom Destinations jump list parser with Windows 10 support

Language:C#License:MITStargazers:0Issues:0Issues:0
Language:PowerShellLicense:MITStargazers:0Issues:0Issues:0

LawEnforcementResources

Resources provided by the community that can serve to be useful for Law Enforcement worldwide

License:MITStargazers:0Issues:0Issues:0

LECmd

Lnk Explorer Command line edition!!

Language:C#License:MITStargazers:0Issues:0Issues:0

MFTECmd

Parses $MFT from NTFS file systems

Language:C#License:MITStargazers:0Issues:0Issues:0

nextron-helper-scripts

Public tools, scripts or code snippets that can help when working with our products

Language:PowerShellStargazers:0Issues:0Issues:0

open-DFIR-pol-proc

A collaboration to develop robust policies and procedures for DFIR labs

License:MITStargazers:0Issues:0Issues:0
Language:C#License:MITStargazers:0Issues:0Issues:0
Language:C#License:MITStargazers:0Issues:0Issues:0

thor-manual

THOR Scanner User Manual

Language:PythonStargazers:0Issues:0Issues:0