Martin Willing's repositories
MemProcFS-Analyzer
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
Collect-MemoryDump
Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
Microsoft-Analyzer-Suite
A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID
Get-MiniTimeline
Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE
scripting-snippets
Repository containing shell and python scripting snippets from evild3ad.
yara-rules
Repository containing YARA rules from evild3ad.
Get-UsnJrnlInfo
Get-UsnJrnlInfo - Get UsnJrnl Information from extracted $Max file
Microsoft-Extractor-Suite
A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.