GithubHelp home page GithubHelp logo

afot's Introduction

Automation FOrensics Tool

The Automation FOrensics Tool (AFOT) is an automation tool build in Python and used for Windows Forensics in order to combine the following tools:

Requirements

The script makes use of Python version 2.7, but it will most likely work with Python 3. You will need to have PIP installed in your system. Please see python docs for details.

You should have your own a VirusTotal api key. Just create an account in VirusTotal website and grab the api key. Then add it as the __VIRUSTOTALAPIKEY__ value.

Usage

Just run python afot.py in your terminal.

Procedure

So the procedure is pretty straight-forward:

  • The user provides the path, which will be used to analyze all the executables included in those folders/subfolders.
  • AnalyzePESig looks for signed executables, whom certificate will soon be revoked.
  • AFOT will collect all the non-signed executables and cross-check them with NSRL's hashset database, using the NSRL tool.
  • Last but not least, if any hashes were found to be in NSRL's hashset database too, we cross-check those hashes with VirusTotal, using the VirusTotal Search tool.

Contributing

Please see CONTRIBUTING for details.

License

The MIT License (MIT). Please see License File for more information.

afot's People

Contributors

harris21 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.