Martin Willing's repositories
MemProcFS-Analyzer
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
Collect-MemoryDump
Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
Get-MiniTimeline
Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE
yara-rules
Repository containing YARA rules from evild3ad.
scripting-snippets
Repository containing shell and python scripting snippets from evild3ad.
Get-UsnJrnlInfo
Get-UsnJrnlInfo - Get UsnJrnl Information from extracted $Max file