Hands-on projects for beginners to learn and practice Windows forensics and essential cybersecurity skills
-
Updated
Jun 29, 2024
Hands-on projects for beginners to learn and practice Windows forensics and essential cybersecurity skills
Cross-platform registry browser for raw Windows registry files
Windows forensics Engine
ExeSpy is a cross-platform PE viewer for EXE and DLL files
Vault of Windows Registry forensic artifacts
Rust DFIR tool that massively parses cross-platform evidence, even deleted logs, into a lateral movement timeline and graph database.
A comprehensive MCP server for Windows digital forensics on KALI Linux
A DFIR Incident Response AI bot using local Ollama LLM to derrive automated findings from logs
Command Spy is a utility for monitoring the command line arguments of new processes on Windows. Made for CCDC.
Tools and Techniques for Digital Forensics and Incident Response
Python module for forensic analysis of Windows shortcuts (LNK files). You can install this package using pip install lnkanalyser
Windows forensic scanner. Finds what "Uninstall" leaves behind.
A comprehensive repository for CyberOps documentation, Blue Team playbooks, and open-source forensic tools like Cerberus and Chimera.
When conducting an investigation on a Windows machine there are 8 phase to go through, today we’ll discuss the first ‘Collecting Volatile Information’, and the rest will be explained in future topics
Search artifact paths, build collection scripts, and convert Sigma rules. All in one place.
EVTX forensic library suite — carve records from corrupt files, detect tampering indicators, analyze ETW sessions. No runtime deps.
Windows Forensic Triage Tool is a Python-based framework that automates forensic artifact collection, evidence analysis, digital signature verification, and HTML report generation to support incident response investigations.
Useful tools for (not only) digital forensics
Ferramenta forense local para verificação (SS) em comunidades de Roblox. 62 scanners, execução totalmente local, sem envio de dados.
Local-first DFIR investigation platform for centralizing artifacts, reducing noise, and reconstructing incidents.
Add a description, image, and links to the windows-forensics topic page so that developers can more easily learn about it.
To associate your repository with the windows-forensics topic, visit your repo's landing page and select "manage topics."