DFIR @ Unit 42, Admin of the Digital Forensics Discord Server, AboutDFIR.com Contributor, USMC Veteran, Former LE.
The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.
HTML - Released: 31 Jan 2022 - 533
A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update. Use these CSVs to create your own known good hash sets!
Released: 13 Nov 2021 - 133
Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!
PowerShell - Released: 22 Jan 2022 - 40
A C# (.NET 6) tool to compare the file signature of files recursively and inform the user of matches and mismatches
C# - Released: 12 Mar 2023 - 15
A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools
PowerShell - Released: 05 Jul 2021 - 50
A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update.
Released: 23 Nov 2021 - 41
A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.
Released: 02 May 2021 - 38
A command-line application to extract (recursively, if needed) IDv3 metadata from audio files
C# - Released: 26 Jun 2023 - 1
A PowerShell script that can be used to parse and convert to CSV the new Windows 11 artifacts found in C:\Windows\appcompat\pca
PowerShell - Released: 18 Jun 2023 - 8
A simple tool to enumerate useful details from CSV files recursively from a provided folder path
C# - Released: 31 Aug 2023 - 2