GithubHelp home page GithubHelp logo

Welcome to my GitHub Profile!

Stats Card: https://github.com/anuraghazra/github-readme-stats

Streak Card: https://github.com/DenverCoder1/github-readme-streak-stats

Top Languages Card: https://github.com/anuraghazra/github-readme-stats

Current Events

Notable GitHub Repositories

Check out my repositories as I have a lot going on all the time!

My most actively maintained projects can be found here.

Forked/Updated DFIR Tools

I enjoy finding abandoned DFIR tools/projects on GitHub and performing basic updates to keep them relevant and useful to the DFIR community. Check out all the tools I've forked and updated (to varying degrees) here. If you have any ideas of tools or scripts that are long overdue for a tuneup, please let me know!

Projects That Need Updating

If you think the Forked/Updated DFIR Tools list is cool, here is a list of tool repositories that may be transferred to that list someday! Think of this list as a to-do list for me to add more tools to the Forked/Updated DFIR Tools list. Check out my Projects That Need Updating list here.

Side Projects

AboutDFIR

I have been a Contributor to AboutDFIR since late 2019. Be sure to check out the best DFIR resource on the planet! Let us know if you have any suggestions via the Site Feedback Form!

Digital Forensics Discord Server

Join the Digital Forensics Discord Server! Check out my beginner's guide here! Also, check out the Digital Forensics Discord Server's GitHub Organization here where there's lots of cool ongoing projects!

Books

The Hitchhiker's Guide to DFIR: Experiences From Beginners and Experts

The Digital Forensics Discord Server produced a crowdsourced book on August 15, 2022. Check it out here!

EZ Tools Manuals

Eric Zimmerman and I co-authored and published the EZ Tools Manuals on Leanpub! Check it out here!

Binary Foray

Eric Zimmerman's posts from his Binary Foray blog are now in PDF and EPUB format. Check it out here!

Andrew Rathbun's Projects

sighunter icon sighunter

A C# (.NET 6) tool to compare the file signature of files recursively and inform the user of matches and mismatches

sigma icon sigma

Generic Signature Format for SIEM Systems

sof-elk icon sof-elk

Configuration files for the SOF-ELK VM, used in SANS FOR572

spectre.console icon spectre.console

A .NET library that makes it easier to create beautiful console applications.

sqlecmd icon sqlecmd

This repository serves as a place for community created SQLECmd Maps for use with SQLECmd.

thehitchhikersguidetodfirexperiencesfrombeginnersandexperts icon thehitchhikersguidetodfirexperiencesfrombeginnersandexperts

The official repo for a project involving a crowdsourced DFIR book. The main purpose of this book is to give anyone interested an opportunity to write a chapter of a book to get their name out there, get a publication on their resume with an actual ISBN number, and ideally lower the bar for people to contribute something back to the DFIR Community. Want to write a chapter? Let me know and let's make it happen!

threathunt icon threathunt

ThreatHunt is a PowerShell repository that allows you to train your threat hunting skills.

timeapp icon timeapp

Simple time and public IP app, useful for recording the screen while interacting with a computer for later corroboration of artifacts against time

tlefileplugins icon tlefileplugins

Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/tag column, layout support, searching, etc.)

usb-detector icon usb-detector

Blue team security tool to help detect physical attacks using USB devices.

usb-explorer icon usb-explorer

A tool that reads data stored under USBSTOR key in the system registry hive, representing information about connected USB storage devices

vanillawindowsreference icon vanillawindowsreference

A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update. Use these CSVs to create your own known good hash sets!

vanillawindowsregistryhives icon vanillawindowsregistryhives

A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update.

w32regactionparser icon w32regactionparser

Parses Win32_RegistryAction entries from WMI. Portable, modern and simple-to-use GUI application for Windows 7/10.

win-for icon win-for

Windows Forensics Environment Builder

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    šŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. šŸ“ŠšŸ“ˆšŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ā¤ļø Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.