Martin Willing (evild3ad)

evild3ad

Geek Repo

Location:Hanover, Germany

Home Page:https://www.evild3ad.com

Twitter:@evild3ad79

Github PK Tool:Github PK Tool

Martin Willing's repositories

MemProcFS-Analyzer

MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR

Language:PowerShellLicense:GPL-3.0Stargazers:401Issues:20Issues:26

Collect-MemoryDump

Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR

Language:PowerShellLicense:GPL-3.0Stargazers:213Issues:6Issues:2

Microsoft-Analyzer-Suite

A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID

Language:PowerShellLicense:GPL-3.0Stargazers:106Issues:1Issues:0

isodump

isodump - ISO dump utility

Language:PythonLicense:GPL-3.0Stargazers:35Issues:4Issues:0

Get-MiniTimeline

Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE

Language:PowerShellLicense:MITStargazers:22Issues:3Issues:0

scripting-snippets

Repository containing shell and python scripting snippets from evild3ad.

Language:ShellStargazers:5Issues:2Issues:0

yara-rules

Repository containing YARA rules from evild3ad.

Get-UsnJrnlInfo

Get-UsnJrnlInfo - Get UsnJrnl Information from extracted $Max file

Language:PowerShellLicense:GPL-3.0Stargazers:3Issues:2Issues:0

Microsoft-Extractor-Suite

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Language:PowerShellLicense:GPL-2.0Stargazers:2Issues:0Issues:0

rules

Repository of yara rules

Language:ShellLicense:GPL-2.0Stargazers:0Issues:2Issues:0

yara

YARA rules for MemProcFS-Analyzer

Language:YARAStargazers:0Issues:2Issues:0