File and file meta information collect using PowerShell in Live Response environment.
-
Updated
Oct 16, 2020 - Python
File and file meta information collect using PowerShell in Live Response environment.
A Firefox extension to encrypt files downloaded through Microsoft 365 Defender's Live Response Sessions.
This is a Live Response script to help incident responders to acquire data, contain and recover.
Parse IIS applicationHost.config to generate CSV file.
Incident Forensic Response In Terminal script for linux
unix_collector is a Live Response collection script for Incident Response on UNIX-like systems using native binaries. Supports AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.
Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
Add a description, image, and links to the live-response topic page so that developers can more easily learn about it.
To associate your repository with the live-response topic, visit your repo's landing page and select "manage topics."