yk's repositories

ArtifactExtractor

Extract common Windows artifacts from source images and VSCs

Language:PythonLicense:Apache-2.0Stargazers:60Issues:8Issues:8

BulkStrike

BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.

Language:PythonLicense:MITStargazers:41Issues:6Issues:6

evtx2json

evtx2json extracts events of interest from event logs, dedups them, and exports them to json.

Language:PythonLicense:Apache-2.0Stargazers:39Issues:6Issues:2

4n6_misc

Miscellaneous Scripts

Language:PythonStargazers:17Issues:2Issues:0

autoripy

Attempt to replicate the functions of auto_rip by Corey Harrell in Python.

macOSParsers

Scripts that parse macOS data objects

Language:PythonLicense:GPL-3.0Stargazers:4Issues:3Issues:1

GCP-IR-Notes

GCP IR Notes

Language:Jupyter NotebookStargazers:2Issues:1Issues:0

Windows-Event-Log-Messages

Retrieves the definitions of Windows Event Log messages embedded in Windows binaries and provides them in discoverable formats. #nsacyber

Language:C#License:NOASSERTIONStargazers:1Issues:0Issues:0

EVTXtract

EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

fbclicker

fbclicker is a set of scripts (currently only 1) to automate browsing activities on Facebook using Selenium.

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

HFSMount

Scripts that mount and unmount HFS e01 images; based on SANS FOR518 method 1

Language:PythonStargazers:0Issues:1Issues:0

SeeMore

Google Chrome browser extension that expands FaceBook posts.

Language:JavaScriptLicense:Apache-2.0Stargazers:0Issues:1Issues:0
Stargazers:0Issues:1Issues:0

Windows-Prefetch-Parser

Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0