Category: Forensics

Kansa

Kansa: A Powershell incident response framework

Kansa A modular incident response framework in Powershell, useful for data collection and analysis. What does it do? It uses Powershell Remoting to run user-contributed, ahem, user-contributed modules across hosts in...

lsrootkit

lsrootkit: Rootkit Detector for UNIX

lsrootkit Rootkit Detector for UNIX (the actual beta only works as expected in Linux) Features The idea is very simple: a lot of rootkits uses a MAGIC GID (a random...

DATA

DATA: Credential Phish Analysis and Automation

DATA: Credential Phish Analysis and Automation Download git clone https://github.com/hadojae/DATA.git BUCKLEGRIPPER (py) Given a suspected phishing url or file of line separated urls, visit, screenshot, and scrape for interesting files. Requirements...

pytbull

Pytbull: IDS/IPS testing framework

Pytbull is a python based flexible IDS/IPS testing framework shipped with more than 300 tests, grouped in 9 modules, covering a large scope of attacks (clientSideAttacks, testRules, badTraffic, fragmentedPackets, multipleFailedLogins,...

PSHunt

PSHunt: Powershell Threat Hunting Module

PSHunt PSHunt is a Powershell Threat Hunting Module designed to scan remote endpoints* for indicators of compromise or survey them for more comprehensive information related to the state of those...

ntdsxtract

ntdsxtract: Active Directory forensic framework

ntdsxtract – Active Directory forensic framework This framework was developed by the author in order to provide the community with a solution to extract forensically important information from the main database...

Red Team Automation

RTA: Red Team Automation

Red Team Automation (RTA) RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK. RTA is composed of...