James Habben's repositories
sysmon-queries
Queries to parse sysmon event log file with microsoft logparser
FirefoxCache2
Python scripts for parsing the index file and individual cache files from the cache2 folder of Firefox defaulted on in version 32
4n6-app-finder
Web app built to allow digital forensic professionals to search for the forensic tools that will parse artifacts from various apps.
EnCaseNetworkFramework
This is a framework written in EnScript to utilize the network capabilities of EnCase. The purpose is to allow for someone to build a quick network enabled EnScript to respond quickly to threats with minimal code being written.
ccm-rua-enscript
EnScript to find and parse CCM_RecentlyUsedApps records
Windows-Prefetch-Parser
Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files
HelpfulPython
Various Python scripts that are helpful for me
ClogFirefoxParser
Use this python script to parse the log file for KeyUp or KeyDown events and print the characters that were typed
RegRipper2.8
RegRipper version 2.8
ALEAPP
Android Logs Events And Protobuf Parser
iLEAPP
iOS Logs, Events, And Plist Parser
kaitai_struct_formats
Kaitai Struct: library of binary file formats (.ksy)
PowerForensics
PowerShell - Live disk forensics platform
RLEAPP
Returns Logs Events And Properties Parser
volatility
An advanced memory forensics framework