Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View jamdunnDFW's full-sized avatar

Block or report jamdunnDFW

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files

Python 121 28 Updated May 29, 2024
Python 278 93 Updated Apr 6, 2023

Forensic tool that parses AppCompatibility key more known as Shimcache, and returns all it's content.

PowerShell 2 Updated May 17, 2019

Win 10/11 related research

PowerShell 193 31 Updated Dec 19, 2023

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Python 748 106 Updated Apr 6, 2025

Invoke-LiveResponse

PowerShell 149 29 Updated Feb 22, 2022

A Windows Event Processing Utility

Python 47 3 Updated Feb 21, 2018

Automated, Collection, and Enrichment Platform

PowerShell 325 62 Updated Nov 14, 2019

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

JavaScript 32,995 3,712 Updated Aug 6, 2025

The start of a be-all end-all for Linux mounting of VMDK's, EWF's, and dd's

Shell 8 4 Updated Jul 14, 2017

openioc_scan Volatility Framework plugin

Python 43 5 Updated Feb 25, 2016

Libewf is a library to access the Expert Witness Compression Format (EWF)

C 289 79 Updated Aug 28, 2024

An informational repo about hunting for adversaries in your IT environment.

1,826 388 Updated Nov 17, 2021

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

JavaScript 7,161 1,121 Updated Oct 31, 2025

Repository of yara rules

YARA 4,564 1,044 Updated Apr 17, 2024

Slides and Other Resources from my latest Talks and Presentations

24 8 Updated Sep 17, 2025

Log newly created WMI consumers and processes to the Windows Application event log

PowerShell 124 19 Updated Feb 28, 2018

GRR Rapid Response: remote live forensics for incident response

Python 4,990 791 Updated Jun 5, 2025

Presentation Archives for my macOS and iOS Related Research

257 35 Updated Mar 18, 2025

An advanced memory forensics framework

Python 7,864 1,338 Updated May 16, 2025

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digi…

C++ 2,915 658 Updated Oct 31, 2025

Super timeline all the things

Python 1,953 402 Updated Oct 28, 2025