Debugging
Debugging utilities
analyzing lnk file and jump list artifacts
GitHubAnalyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution,
analyzing macro malware in office documents
GitHub'Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download
analyzing malware behavior with cuckoo sandbox
GitHub'Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system
analyzing malware persistence with autoruns
GitHubUse Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry
analyzing mft for deleted file recovery
GitHubAnalyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record
analyzing network covert channels in malware
GitHubDetect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration,
analyzing network traffic for incidents
GitHub'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
analyzing network traffic of malware
GitHub'Analyzes network traffic generated by malware during sandbox execution or live incident response to identify
analyzing office365 audit logs for compromise
GitHubParse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation,
analyzing outlook pst for email forensics
GitHubAnalyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments,
analyzing pdf malware with pdfid
GitHub'Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode,
analyzing persistence mechanisms in linux
GitHubDetect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD
analyzing powershell empire artifacts
GitHubDetect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns,
analyzing ransomware leak site intelligence
GitHubMonitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence
analyzing ransomware network indicators
GitHubIdentify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration
analyzing slack space and file system artifacts
GitHubExamine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data
analyzing threat actor ttps with mitre attack
GitHubMITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs)
analyzing typosquatting domains with dnstwist
GitHubDetect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations
analyzing usb device connection history
GitHubInvestigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable
analyzing windows amcache artifacts
GitHub'Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application
analyzing windows lnk files for artifacts
GitHubParse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers
analyzing windows registry for artifacts
GitHubExtract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and
auditing azure active directory configuration
GitHub'Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies,
auditing kubernetes cluster rbac
GitHub'Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous