Python tool development project to help detect and synthesize the behavior of malicious code, especially fileless malware during the CA process.
-
Updated
Apr 16, 2024 - Python
Python tool development project to help detect and synthesize the behavior of malicious code, especially fileless malware during the CA process.
Windows Forensic Triage Tool is a Python-based framework that automates forensic artifact collection, evidence analysis, digital signature verification, and HTML report generation to support incident response investigations.
macOS DFIR Artifact Collector — single-file, zero-dependency, modular collection script with selective module execution and supply-chain IOC sweeps.
A comprehensive PowerShell tool for security analysts and incident responders that systematically collects Windows event logs, system information, network data, and forensic artifacts into organized ZIP archives for security analysis and investigation.
Single-file PowerShell Incident Response and DFIR triage collector for Windows. Gathers high-value forensic artifacts into one timestamped, hashed, packaged output. Defensive and authorized use only.
Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks correlation. 20+ modules mapped to MITRE ATT&CK.
Powerful investigation toolkit for deeper forensic analysis
ForensicTools automatise l’acquisition forensique multi-plateforme (Windows, Linux, macOS) : collecte d’artefacts volatils et persistants, capture mémoire, copie bit-à-bit des disques, chaîne de custody, gestion des dossiers d’enquête et orchestration d’outils d’analyse (Volatility3, Plaso, YARA, Sleuth Kit).
A modular Windows DFIR artifact collection tool written in Go for incident response and response triage. Supports memory, NTFS, registry, event logs, and more.
To associate your repository with the artifact-collection topic, visit your repo's landing page and select "manage topics."