Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.
-
Updated
Aug 10, 2019 - C
Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.
CDIR (Cyber Defense Institute Incident Response) Collector - live collection tool based on oss tool/library
A port of Kaitai to the Hiew hex editor
dcfldd - enhanced version of dd for forensics and security
Trace ScriptBlock execution for powershell v2
Proof-of-Concept to evade auditd by writing /proc/PID/mem
Proof-of-Concept to evade auditd by tampering via ptrace
This repo hosts basic win32 compatible and visual studio C based shell code for an article on analysis
A GPS Forensics Utility to Parse GPX Files
Add a description, image, and links to the dfir topic page so that developers can more easily learn about it.
To associate your repository with the dfir topic, visit your repo's landing page and select "manage topics."