Andrew Rathbun (AndrewRathbun)

AndrewRathbun

Geek Repo

Company:@krollcyber

Location:Michigan

Home Page:https://aboutdfir.com/

Twitter:@bunsofwrath12

Github PK Tool:Github PK Tool


Organizations
Digital-Forensics-Discord-Server

Andrew Rathbun's repositories

VanillaWindowsReference

A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update. Use these CSVs to create your own known good hash sets!

DFIRPowerShellScripts

Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!

Language:PowerShellLicense:MITStargazers:40Issues:3Issues:6

DirectoryOpus-DFIRConfig

A config file that's curated for DFIR examiners with shortcuts to common Windows artifacts and settings enabled that help make your life easier with various file management tasks.

RAMDumpExplorer

An updated fork of @bacanoicua's RAMDumpExplorer project. This is a program designed to analyze a dump of the RAM memory to search for potentially malicious files. The program scans the dump file for specific patterns and uses regular expressions to identify and extract the matched values

Language:C#License:GPL-3.0Stargazers:5Issues:1Issues:0

DFIR-Triage-Collector

Rapid DFIR Triage Collection Tool For Windows, Mac and Linux

Language:C#Stargazers:3Issues:0Issues:0

WinTools

A collection of free miscellaneous Windows tools

Language:C#License:MITStargazers:3Issues:0Issues:0

CSVFileDetailsExtractor

A simple tool to enumerate useful details from CSV files recursively from a provided folder path

Language:C#License:MITStargazers:2Issues:2Issues:0

iADForensics

iADForensics - ESE NTDS.DIT Database forensics framework

Language:C#License:MITStargazers:2Issues:0Issues:0

LikeNtfsWalker

ToyProject_Like NTFSwalker

Language:C#Stargazers:2Issues:0Issues:0

PEExplorer

Portable Executable Explorer

Language:C#Stargazers:2Issues:0Issues:0

RECmd

Command line access to the Registry

Language:RebolLicense:MITStargazers:2Issues:2Issues:0

SQLECmd

This repository serves as a place for community created SQLECmd Maps for use with SQLECmd.

Language:C#License:MITStargazers:2Issues:2Issues:0

BinReveal

An updated fork of @MTJailed's BinReveal project. This is a project for analyzing files to find signatures or hidden files in a file

Language:C#License:MITStargazers:1Issues:0Issues:0

CsvMerger

A simple program to merge CSV files together.

Language:C#License:MITStargazers:1Issues:2Issues:0

DateDecoder

An updated fork of DateDecoder originally by @jacobsoo.

Language:C#Stargazers:1Issues:0Issues:0
Language:C#License:MITStargazers:1Issues:1Issues:0
Language:C#License:MITStargazers:1Issues:0Issues:0

PurpleSharp

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows environments

Language:C#License:BSD-3-ClauseStargazers:1Issues:0Issues:0
Language:C#License:MITStargazers:1Issues:1Issues:0

TLEFilePlugins

Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/tag column, layout support, searching, etc.)

Language:C#License:MITStargazers:1Issues:0Issues:0
Language:C#License:NOASSERTIONStargazers:0Issues:0Issues:0

iisGeolocate

geolocate ip addresses in IIS logs

Language:C#License:MITStargazers:0Issues:0Issues:0

JLECmd

Automatic and Custom Destinations jump list parser with Windows 10 support

Language:C#License:MITStargazers:0Issues:0Issues:0

OleCf

Library to process OLE compound file format. This is a work in progress and was initially written for jumplist parsing (for which it does fine)

Language:C#License:MITStargazers:0Issues:0Issues:0

PECmd

Prefetch Explorer Command Line

Language:C#License:MITStargazers:0Issues:0Issues:0

RBCmd

Recycle bin artifact parser

Language:C#License:MITStargazers:0Issues:0Issues:0

Registry

Full featured, offline Registry parser in C#

Language:C#License:MITStargazers:0Issues:0Issues:0
Language:C#License:MITStargazers:0Issues:0Issues:0
Language:C#License:MITStargazers:0Issues:1Issues:0

WPF-Samples

Repository for WPF related samples

Language:C#License:MITStargazers:0Issues:1Issues:0