Jean-Philippe's starred repositories

macOS-Security-and-Privacy-Guide

Guide to securing and improving privacy on macOS

opencti

Open Cyber Threat Intelligence Platform

Language:TypeScriptLicense:NOASSERTIONStargazers:6261Issues:139Issues:5172

cloudmapper

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

Language:JavaScriptLicense:BSD-3-ClauseStargazers:5981Issues:135Issues:540

EVTX-ATTACK-SAMPLES

Windows Events Attack Samples

Language:HTMLLicense:GPL-3.0Stargazers:2215Issues:144Issues:12

malleable-c2

Cobalt Strike Malleable C2 Design and Reference Guide

zsign

Maybe it is the most quickly codesign alternative for iOS12+, cross-platform ( macOS, Linux , Windows ), more features.

Language:C++License:BSD-3-ClauseStargazers:1270Issues:49Issues:229

cloudtracker

CloudTracker helps you find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies.

Language:PythonLicense:BSD-3-ClauseStargazers:885Issues:26Issues:51

isign

Code sign iOS applications, without proprietary Apple software or hardware

Language:PythonLicense:NOASSERTIONStargazers:755Issues:50Issues:105

APOLLO

Apple Pattern of Life Lazy Output'er

Language:PythonLicense:NOASSERTIONStargazers:555Issues:51Issues:12

automactc

AutoMacTC: Automated Mac Forensic Triage Collector

Language:PythonLicense:NOASSERTIONStargazers:524Issues:72Issues:9

analyzeMFT

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Language:PythonLicense:MITStargazers:436Issues:35Issues:79

SwiftBelt

A macOS enumeration tool inspired by harmjoy's Windows-based Seatbelt enumeration tool. Author: Cedric Owens

Language:SwiftLicense:BSD-3-ClauseStargazers:316Issues:15Issues:3

userline

Query and report user logons relations from MS Windows Security Events

Language:PythonLicense:BSD-3-ClauseStargazers:240Issues:28Issues:2

FSEventsParser

Parser for OSX/iOS FSEvents Logs

Language:PythonLicense:Apache-2.0Stargazers:234Issues:23Issues:8

AnalyzePDF

Tool to help analyze PDF files

IOCextractor

IOC (Indicator of Compromise) Extractor: a program to help extract IOCs from text files.

DFIR-SQL-Query-Repo

Collection of SQL query templates for digital forensics use by platform and application.

jager

Hunting IOCs all day every day...

Language:Jupyter NotebookLicense:NOASSERTIONStargazers:82Issues:10Issues:33

PyPDNS

Client API to query any Passive DNS implementation following the Passive DNS - Common Output Format.

Language:PythonLicense:NOASSERTIONStargazers:75Issues:20Issues:2

TS-Security-Editor

Terminal Service (RDP) Security Editor

Language:C++License:BSD-3-ClauseStargazers:47Issues:5Issues:1

quarantine-formats

Documentation and parsers for different anti-virus quarantine formats.

time_decode

A timestamp and date decoder written for python 3

Language:PythonLicense:MITStargazers:34Issues:2Issues:8

YaraRules

Multiple rules for yara-project for detect compiler/packer/protector

Language:YARAStargazers:33Issues:13Issues:0

ircollect

ircollect

Language:PythonLicense:Apache-2.0Stargazers:31Issues:6Issues:2

winsddl

Windows Security Descriptor Definition Language (SDDL) parser and formatter

Language:PythonStargazers:9Issues:3Issues:0

VBNExtract

Extract SEP VBN quarantine files

Language:CLicense:GPL-3.0Stargazers:6Issues:3Issues:0