Fernando Tomlinson's repositories

PoSh-R2

PowerShell - Rapid Response... For the incident responder in you!

Language:PowerShellLicense:Apache-2.0Stargazers:290Issues:34Issues:2

PowerShell

A series of scripts

Language:PowerShellStargazers:93Issues:18Issues:0

Invoke-HiveNightmare

PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version 1809 or newer

Language:PowerShellStargazers:35Issues:2Issues:0

AutomatedProfiler

Automated forensics written in PowerShell

Language:PerlLicense:Apache-2.0Stargazers:32Issues:10Issues:0
Language:PowerShellStargazers:12Issues:2Issues:0

Invoke-SRUMDump

A pure PowerShell/ .NET DFIR capability that dumps the Windows SRUM (System Resource Usage Monitor) database to CSVs for analysis.

Language:PowerShellStargazers:12Issues:1Issues:0

Invoke-Fail2Ban

PowerShell version of Fail2Ban

TeamViewer_Forensics

A series of functions to parse Teamviewer logs to answer specific questions

Language:PowerShellStargazers:9Issues:3Issues:0

Invoke-AZExplorer

Microsoft Azure Survey

Language:PowerShellStargazers:7Issues:2Issues:1

Invoke-GhostLog

Removal of certain event logs within a Windows OS

Language:PowerShellStargazers:7Issues:2Issues:0
Language:PowerShellStargazers:5Issues:2Issues:0

Invoke-Unbup

Decrypts McAfee quarantine files

Language:PowerShellStargazers:5Issues:2Issues:0

EventLog_Parsers

Series of scripts to parse the event log for analysis

Language:PowerShellStargazers:4Issues:2Issues:0

Invoke-HAFNIUMCheck.ps1

Script used to identify compromise via CVEs 2021-26855, 26857, 26858, and 27065

Language:PowerShellStargazers:4Issues:3Issues:3

Invoke-ProcessSuspend

Suspending Processes using PS

Language:PowerShellStargazers:2Issues:2Issues:0

CVE-Checker

Collection of script to check for CVEs

Language:ShellStargazers:1Issues:2Issues:0

Invoke-HashFinder

Searches for a supplied list of SHA1 or SHA256 hashes on a system. Requires either a file size or creation date that is associated with the binary that the hashes were retrieved from.

Language:PowerShellStargazers:1Issues:2Issues:0

Invoke-HiveDreams

A capability to identify and remediate CVE-2021-36934 (HiveNightmare)

Language:PowerShellStargazers:1Issues:2Issues:0

PoSh-Bitvise-Log-Parser

Parsing Bitvise logs with PowerShell

Language:PowerShellStargazers:1Issues:1Issues:0

FirstAlert

A very simple script to aid in preventing ransomware payloads

Language:PowerShellStargazers:0Issues:3Issues:0

Get-TeamsFiles

Downloads all files that you've ever uploaded to Microsoft Teams

Language:PowerShellStargazers:0Issues:0Issues:0

HiveNightmare

Exploit allowing you to read registry hives as non-admin on Windows 10 and 11

Language:C++Stargazers:0Issues:1Issues:0

Invoke-PSSlack

Slack + PowerShell = :)

Language:PowerShellStargazers:0Issues:2Issues:0
Stargazers:0Issues:2Issues:0

Invoke-SinkholeDomain

Sinkholes domains

Language:PowerShellStargazers:0Issues:2Issues:0

PowerShell-Saturday

This repository is a place to store Speaker content for the Raleigh PowerShell Saturday events.

Stargazers:0Issues:1Issues:0

which-reality

PHP code to determine which reality (Server OS and web app versions) the app is running in (yeah... it's a play on Rick and Morty)

Language:ShellStargazers:0Issues:1Issues:0