Sigma rules to share with the community
Repositórios
Repositórios de tomchop
Digital Forensics artifact repository
In last week's episode of Baking Bad...
Python library to carry out DFIR analysis on the Cloud
DFIQ is a collection of investigative questions and the approaches for answering them
A framework for orchestrating forensic collection, processing and data export
Cross-platform Yara scanner written in Go
Malcom - Malware Communications Analyzer
Extract metadata from files in directory
Miscellaneous repository of scripts and tools
Processes forensic artifacts to generate timelines using Plaso
OpenRelik worker that scans files with Yara rules
Parse YARA rules and operate over them more easily.
Collaborative forensic timeline analysis
tomchop's landing page
Blog
unXOR will search a XORed file and try to guess the key using known-plaintext attacks.