Category: Forensics

investigate windows event logs

epagneul v0.4.1 releases: visualize and investigate windows event logs

epagneul – visualize and investigate windows event logs Changelog v0.4 Added Observable: windows groups Relationships: TGT_DES_REQUEST, TGT_AES_REQUEST, TGT_RC4_REQUEST Users ranking Changed Better management of Relationships and Observables Edges labels are now more generic (instead...

suspicious file finder

fastfinder: Fast suspicious file finder

FastFinder – Incident Response – Fast suspicious file finder FastFinder is a lightweight tool made for threat hunting, live forensics, and triage on both Windows and Linux Platforms. It is focused on endpoint enumeration and...

Windows Event Log Analyzer

WELA: Windows Event Log Analyzer

WELA (Windows Event Log Analyzer) Yamato Security’s WELA(Windows Event Log Analyzer) aims to be the Swiss Army knife for Windows event logs. Currently, WELA’s greatest functionality is creating an easy-to-analyze logon timeline in order...

Winshark

Winshark: wireshark plugin to instrument ETW

Winshark Wireshark plugin to work with Event Tracing for Windows Microsoft Message Analyzer is being retired and its download packages were removed from microsoft.com sites on November 25, 2019. Wireshark has built a huge library...

Incident Response Collection

Incident Response Collection Protocol

Incident Response Collection Protocol (IRCP) A series of PowerShell scripts to automate artifact collection & assist Responders triaging endpoints in lab-based & onsite environments. IRCP Features IRCP supports E01, VMDK, VHD, VHDX images &...

leak site monitoring

ransomwatch: ransomware leak site monitoring tool

RansomWatch RansomWatch is a ransomware leak site monitoring tool. It will scrape all of the entries on various ransomware leak sites, store the data in an SQLite database, and send notifications via Slack or...