Skip to content

This space contains scripts I have created to try to automate basic analysis or triage for incident evidence.

License

Notifications You must be signed in to change notification settings

edchavarro/DFIR_scripts

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

DFIR_scripts

This space contains scripts I have created to try to automate basic analisys or triage for incident evidence.

It works for me, maybe could be useful for you.

#evidence-parser

Powershell scripts that executes and stores the results for executing common tools like #RegRipper, #MFTAnalyze and Plazo to evidence collectedd using velociraptor. It requires the file WindowsEventID.txt to look for specific strings, you casn improve this file for better results.

#pssigma-check

An script where I try to improve results from SIGMA for my own analysis. Still working on it :)

About

This space contains scripts I have created to try to automate basic analysis or triage for incident evidence.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published