-
Unit 42
- Michigan
-
00:35
(UTC -04:00) - @bunsofwrath12
Highlights
- Pro
Lists (14)
Sort Name ascending (A-Z)
C# Libraries
DFIR Tools to Test Drive
Docker Stuff
EZ Tools
All repositories related to Eric Zimmerman's Toolsfoorbar2000 Components
Forked/Updated DFIR Tools
A list of tools (mostly C#) that I've forked and updated dependencies, compiled/signed a binary, updated the README, and in some instances, improved the tool!Helpful Tools
These are tools I've used to help parse uncommon artifacts or perform a very helpful task in an investigation.✨ Inspiration
KAPE
A list of KAPE-related repositories as well as repositories for EZ Tools that should be updated frequently (along with KAPE).🚀 My projects
A list of projects I've started and/or actively maintainNon-DFIR Tools to Test Drive
Projects That Need Updating
A list of repos that contain tools that I want to spend some time on in the future and update dependencies, push out a new release, or improve in some other wayStream Deck Plugins
GitHub repositories for Stream Deck plugins I useUseful Discord bots
Starred repositories
A skill to stop your coding agent from burying the answer. ADHD-friendly output.
Volatility 3 ported to Rust. Same output, much faster.
Autonomous DFIR agent — SANS SIFT Workstation MCP server for incident response
Draft a post once and format it for LinkedIn, X, Bluesky, Threads, Mastodon, Facebook, and Instagram — each platform's length and formatting limits applied live. Plus a LinkedIn-only browser extens…
Generate realistic synthetic security logs for cybersecurity threat hunting training and research
UAL Timeline Generator — User Access Logging Timeliner
Manage Elgato Prompter scripts from CLI or local web GUI: import, export, rename, reorder, backup, restore.
Miller is like awk, sed, cut, join, and sort for name-indexed data such as CSV, TSV, and tabular JSON
TinyToolTown is a place for stupid-delightful tools made with love. Free, fun & open source. Made for an audience of one.
Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mode (Arrow/DuckDB) for 10M+ events.
macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR
A lightweight tool to view, search and analyze registry hives
Find, verify, and analyze leaked credentials
Forensic Browser History Analyzer - Cross-platform browser history extractor (Chrome, Firefox, IE/Edge, Brave, Opera, Vivaldi)
OBS Studio - Free and open source software for live streaming and screen recording
DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt, process inspection, lateral movement tracking, persist…
This educational repository showcases the most common vulnerabilities found in .NET applications
An overhauled script to turn an Ubuntu 24.04 LTS VM into a Forensics workstation with a light flare of penetration testing tools onboard.
WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing and configuring Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Resp…
This repository is used to store useful information regarding of the RMM forensics investigation.
Force Remove Copilot, Recall and More in Windows 11





