yk's starred repositories

yari

YARI is an interactive debugger for YARA Language.

Language:RustLicense:MITStargazers:85Issues:0Issues:0

Tempo

A lightweight timestamp decoder for MacOS.

Language:PythonLicense:MITStargazers:9Issues:0Issues:0

TangledWinExec

PoCs and tools for investigation of Windows process execution techniques

Language:C#License:BSD-3-ClauseStargazers:858Issues:0Issues:0

ese-analyst

This is a set of tools for doing forensics analysis on Microsoft ESE databases.

Language:PythonStargazers:121Issues:0Issues:0

MemProcFS

MemProcFS

Language:CLicense:AGPL-3.0Stargazers:2737Issues:0Issues:0

security_content

Splunk Security Content

Language:PythonLicense:Apache-2.0Stargazers:1159Issues:0Issues:0

pe-bear

Portable Executable reversing tool with a friendly GUI

Language:C++License:GPL-2.0Stargazers:2465Issues:0Issues:0

cloudfox

Automating situational awareness for cloud penetration tests.

Language:GoLicense:MITStargazers:1820Issues:0Issues:0

Cloud-Investigate

A preconfigured Windows-based system designed for rapid forensic investigations in both Azure and AWS.

Language:HCLLicense:NOASSERTIONStargazers:35Issues:0Issues:0

pe-bear-releases

PE-bear (builds only)

Stargazers:763Issues:0Issues:0

coldsnap

A command line interface for Amazon EBS snapshots

Language:RustLicense:Apache-2.0Stargazers:170Issues:0Issues:0

jackson

🔥 Streamline your web application's authentication with Jackson, an SSO service supporting SAML and OpenID Connect protocols. Beyond enterprise-grade Single Sign-On, it also supports Directory Sync via the SCIM 2.0 protocol for automatic user and group provisioning/de-provisioning. 🤩

Language:TypeScriptLicense:Apache-2.0Stargazers:1626Issues:0Issues:0
Language:PythonStargazers:21Issues:0Issues:0

phishurl-list

Phishing URL dataset from JPCERT/CC

Language:HTMLStargazers:142Issues:0Issues:0
Language:PythonStargazers:18Issues:0Issues:0

aws-security-analytics-bootstrap

AWS Security Analytics Bootstrap enables customers to perform security investigations on AWS service logs by providing an Amazon Athena analysis environment that's quick to deploy, ready to use, and easy to maintain.

License:Apache-2.0Stargazers:223Issues:0Issues:0
Language:RustLicense:Apache-2.0Stargazers:192Issues:0Issues:0

yarang

Alternative YARA scanning engine

Language:C++License:MITStargazers:64Issues:0Issues:0

popeye

👀 A Kubernetes cluster resource sanitizer

Language:GoLicense:NOASSERTIONStargazers:5022Issues:0Issues:0

SANSGoldPaperResearch_FOR500_Rathbun

A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.

Language:HTMLLicense:MITStargazers:24Issues:0Issues:0

wtfis

Passive hostname, domain and IP lookup tool for non-robots

Language:PythonLicense:MITStargazers:848Issues:0Issues:0

al-khaser

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

Language:C++License:GPL-2.0Stargazers:5592Issues:0Issues:0

protections-artifacts

Elastic Security detection content for Endpoint

Language:YARALicense:NOASSERTIONStargazers:895Issues:0Issues:0
Language:GoLicense:Apache-2.0Stargazers:108Issues:0Issues:0
License:MITStargazers:76Issues:0Issues:0

unfurl_jupyter

A patch to the unfurl library to adapt it to a Jupyter Notebook

Language:PythonLicense:Apache-2.0Stargazers:6Issues:0Issues:0

strelka-ui

Strelka Web UI for File Submission and Analysis

Language:JavaScriptLicense:NOASSERTIONStargazers:39Issues:0Issues:0

strelka

Real-time, container-based file scanning at enterprise scale

Language:PythonLicense:NOASSERTIONStargazers:806Issues:0Issues:0

ALFA

ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit logs using statistics and the MITRE ATT&CK Cloud Framework

Language:PythonLicense:MITStargazers:136Issues:0Issues:0

TheHitchhikersGuidetoDFIRExperiencesFromBeginnersandExperts

The official repo for a project involving a crowdsourced DFIR book. The main purpose of this book is to give anyone interested an opportunity to write a chapter of a book to get their name out there, get a publication on their resume with an actual ISBN number, and ideally lower the bar for people to contribute something back to the DFIR Community. Want to write a chapter? Let me know and let's make it happen!

Language:RubyLicense:MITStargazers:184Issues:0Issues:0