Hands-on projects for beginners to learn and practice Windows forensics and essential cybersecurity skills
-
Updated
Jun 29, 2024
Hands-on projects for beginners to learn and practice Windows forensics and essential cybersecurity skills
Cross-platform registry browser for raw Windows registry files
Windows forensics Engine
ExeSpy is a cross-platform PE viewer for EXE and DLL files
Vault of Windows Registry forensic artifacts
A DFIR Incident Response AI bot using local Ollama LLM to derrive automated findings from logs
A comprehensive MCP server for Windows digital forensics on KALI Linux
Tools and Techniques for Digital Forensics and Incident Response
Command Spy is a utility for monitoring the command line arguments of new processes on Windows. Made for CCDC.
Python module for forensic analysis of Windows shortcuts (LNK files). You can install this package using pip install lnkanalyser
A comprehensive repository for CyberOps documentation, Blue Team playbooks, and open-source forensic tools like Cerberus and Chimera.
Rust DFIR tool that massively parses cross-platform evidence, even deleted logs, into a lateral movement timeline and graph database.
Search artifact paths, build collection scripts, and convert Sigma rules. All in one place.
When conducting an investigation on a Windows machine there are 8 phase to go through, today we’ll discuss the first ‘Collecting Volatile Information’, and the rest will be explained in future topics
Windows Forensic Triage Tool is a Python-based framework that automates forensic artifact collection, evidence analysis, digital signature verification, and HTML report generation to support incident response investigations.
Useful tools for (not only) digital forensics
Endpoint investigation of a PowerShell LotL attack reconstructing persistence via Windows services, extracting IOCs, and mapping to MITRE ATT&CK using Kibana and Windows event logs.
From Shadows to Sun: A high-resolution forensics suite for absolute coordinate determination, from triage to testimony.
PowerShell hash lookup against MalwareBazaar & ThreatFox with HTML reports
Zero-dependency DFIR triage script for Windows systems. PowerShell 5.1, no external tools required.
Add a description, image, and links to the windows-forensics topic page so that developers can more easily learn about it.
To associate your repository with the windows-forensics topic, visit your repo's landing page and select "manage topics."