File and file meta information collect using PowerShell in Live Response environment.
-
Updated
Oct 16, 2020 - Python
File and file meta information collect using PowerShell in Live Response environment.
Parse IIS applicationHost.config to generate CSV file.
This is a Live Response script to help incident responders to acquire data, contain and recover.
A Firefox extension to encrypt files downloaded through Microsoft 365 Defender's Live Response Sessions.
An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.
Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
Incident Forensic Response In Terminal script for linux
unix_collector is a Live Response collection script for Incident Response on UNIX-like systems using native binaries. Supports AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
Add a description, image, and links to the live-response topic page so that developers can more easily learn about it.
To associate your repository with the live-response topic, visit your repo's landing page and select "manage topics."