Mark Hallman's repositories

plaso_filters

Scripts to facilitate filtering with Plaso

kape-at-scale

Repo for code, techniques, ideas and questions about implementing KAPE at Scale

DFRWS-2019-KAPE-Workshop

Slides, scripts, notes, link, etc from my 2019 DFRWS KAPE Workshop

Process-EventLogs

Process select Event Logs and Event ID's with EvtxECmd

Language:PowerShellStargazers:7Issues:1Issues:0

Get-KapeModuleBinaries

Parses KAPE module files and downloads binaries referenced by BinaryURL

Language:PowerShellLicense:MITStargazers:1Issues:0Issues:0

scripts_configs

Various scripts and config files

Stargazers:1Issues:0Issues:0

sec401-win11-notes

Notes & scripts related to the SEC401 Windows 11 redo

Language:PowerShellLicense:MITStargazers:1Issues:1Issues:0

evtx

C# based evtx parser with lots of extras

Language:C#License:MITStargazers:0Issues:0Issues:0

HashiCorp-Packer-in-Production

HashiCorp Packer in Production, Published by Packt

License:MITStargazers:0Issues:0Issues:0

kape-min

A sample minimal "install" of KAPE for testing with powershell remoting.

Stargazers:0Issues:0Issues:0

KapeFiles

This repository serves as a place for community created Targets and Modules for use with KAPE.

License:MITStargazers:0Issues:0Issues:0

mdwiki-examples

A collection of example wesbites created with MDwiki

Language:HTMLStargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

sec566-vm-build-notes

Notes, files, and scripts related to the J01 build of SEC566 Windows 11 Audit VM.

Stargazers:0Issues:0Issues:0

timesketch

Collaborative forensic timeline analysis

Language:PythonLicense:Apache-2.0Stargazers:0Issues:0Issues:0
Language:PowerShellStargazers:0Issues:0Issues:0