Glenn's repositories

AnalyzePE

Wraps around various tools and provides some additional checks/information to produce a centralized report of a PE file.

Language:PythonStargazers:201Issues:19Issues:0

AnalyzePDF

Tool to help analyze PDF files

IPinfo

Searches various online resources to try and get as much info about an IP/domain as possible.

NoMoreXOR

Tool to help guess a files 256 byte XOR key by using frequency analysis

Language:PythonStargazers:81Issues:12Issues:0

IR

Some dfir stuff

FileLookup

Quick & dirty script to get info on a file from online resources (VirusTotal, Team Cymru, Shadow Server etc.)

Language:PythonStargazers:30Issues:5Issues:0

yara-goodies

Useful scripts, rules etc. for use with YARA

Language:PythonStargazers:26Issues:9Issues:0
Language:PythonStargazers:5Issues:2Issues:0

hiddenillusion.github.io

Repo for https://hiddenillusion.github.io

bmc-tools

RDP Bitmap Cache parser

Language:PythonLicense:NOASSERTIONStargazers:2Issues:2Issues:0
Language:PythonLicense:GPL-3.0Stargazers:2Issues:1Issues:0

ES-stuff

some elastic search stuff

Language:PythonStargazers:2Issues:1Issues:0

example-code

Some things I found useful along the way

Language:PythonStargazers:2Issues:1Issues:0

timesketch

Collaborative forensics timeline analysis

Language:PythonLicense:Apache-2.0Stargazers:2Issues:3Issues:0
Language:PythonStargazers:1Issues:2Issues:0

appcompatprocessor

"Evolving AppCompat/AmCache data analysis beyond grep"

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

cloud-forensics-utils

Python library to carry out DFIR analysis on the Cloud

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

community

Volatility plugins developed and maintained by the community

Language:PythonStargazers:0Issues:1Issues:0

EventMonkey

A Windows Event Processing Utility

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

INDXParse

Tool suite for inspecting NTFS artifacts.

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

knockknock

Who's there?

Language:PythonLicense:NOASSERTIONStargazers:0Issues:1Issues:0

LfLe

Recover event log entries from an image by heurisitically looking for record structures.

Language:PythonStargazers:0Issues:1Issues:0

liblightgrep

not the worst forensics regexp engine

Language:C++License:GPL-3.0Stargazers:0Issues:1Issues:0

process-forest

Reconstruct process trees from event logs

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

pylzma

Python bindings for the LZMA library

Language:CLicense:LGPL-2.1Stargazers:0Issues:1Issues:0

registrydecoder

This is a copy of the Registry Decoder repository from Google Code.

Language:PythonStargazers:0Issues:1Issues:0

volatility

An advanced memory forensics framework

Language:PythonLicense:GPL-2.0Stargazers:0Issues:1Issues:0

volatility-autoruns

Autoruns plugin for the Volatility framework

Language:PythonLicense:GPL-2.0Stargazers:0Issues:1Issues:0
Language:PythonStargazers:0Issues:1Issues:0

volatility-plugins-1

Plugins I've written for Volatility

Language:PythonStargazers:0Issues:1Issues:0