ForensicITGuy/forensicitguy.github.io
ForensicITGuy Blog
ForensicITGuy Blog
Bringing the Party Parrot to PowerShell
This server enables large language models to interact with Assemblyline v4+ components through a standardized interface for queries, actions, and automation.
Calculate the PE Rich Header MD5 hash
Whitelisting LD_PRELOAD libraries using LD_AUDIT
Small and highly portable detection tests based on MITRE's ATT&CK.
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations secure their infrastructure.
A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.
Configuration files for the SOF-ELK VM
Repository to publish your evasion techniques and contribute to the project
Resources I've found useful for my CTI work
YARA signature and IOC database for my scanners and tools
Hide malware behind a legit process C#
The pattern matching swiss knife
Visual Studio Code extension for MITRE ATT&CK
Malware Analyst Crash Course
A simple Python 3 script to reverse the order of bytes in a file and write the result to a second.
This repository maintains the SaltStack state files for the REMnux distro.
Scripts and tools accompanying HP Threat Research blog posts and reports.
PowerShell tool to lookup AD user info and track down account lockouts in AD domain
Scripts used for a Jupiter Broadcasting Command-Line Threat Hunting Study Group
PowerShell tools to remove IIS logs according to retention policy