Windows DFIR
Rapidly Search and Hunt through Windows Forensic Artefacts
Inspect and capture minidump files. Includes stand alone library for reading minidump files.
Small collection of Ransomware organized by family.
Sysmon configuration file template with default high-quality event tracing
A repository of sysmon configuration modules
Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.
getsystem via parent process using ps1 & embeded c#
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
Library and tools to access the Windows XML Event Log (EVTX) format
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
Parses amcache.hve files, but with a twist!
Event Tracing For Windows (ETW) Resources
A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.




