Skip to content
View chadtilbury's full-sized avatar

Sponsoring

@EricZimmerman
@ufrisk

Block or report chadtilbury

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

DriveFS Sleuth is a Python tool that automates investigating Google Drive File Stream disk artifacts, the tool has been developed based on research that has been performed by mounting different sce…

Python 73 3 Updated Oct 18, 2024

This repository serves as a place for community created Targets and Modules for use with KAPE.

653 193 Updated Oct 30, 2024

Web browser forensics for Google Chrome/Chromium

Python 1,080 141 Updated Oct 28, 2024

Windows Event Log "Microsoft-Windows-Partition%4Diagnostic.evtx" parser and devices' VSNs extractor.

Python 19 2 Updated Nov 28, 2023

Gmail URL Decoder is an Open Source Python tool that can be used against plaintext or arbitrary raw data files in order to find, extract, and decode information from Gmail URLs related to both the …

Python 52 13 Updated Nov 25, 2019

A Windows registry file parser written in Rust

Rust 36 3 Updated Aug 21, 2023

http://moaistory.blogspot.com/2018/10/winsearchdbanalyzer.html

C# 118 14 Updated Jul 20, 2024

OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat and <UserCid>.dat.previous file.

Python 179 17 Updated Nov 1, 2024

Windows.EDB Browser

PowerShell 53 6 Updated Mar 6, 2023

(Sometimes partial) Python re-implementations of the technologies involved in reading various data sources in Chrome-esque applications.

Python 140 34 Updated Sep 11, 2024

Dumps all of the Key/Value pairs from a LevelDB database

Go 63 5 Updated Sep 4, 2023

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

PowerShell 470 67 Updated Oct 29, 2024

XstReader is an open source viewer for Microsoft Outlook’s .ost and .pst files (also those protected by unknown password). You can view and inspect all content and export messages and attachments (…

C# 111 9 Updated Jul 23, 2023

OneDrive log .ODL reader

Python 120 26 Updated Oct 31, 2024

This repository serves as a place for community created Targets and Modules for use with KAPE.

1 Updated Dec 5, 2023

Win 10/11 related research

PowerShell 177 33 Updated Dec 19, 2023

Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)

PowerShell 176 23 Updated Feb 16, 2023
Python 19 5 Updated Jun 7, 2023

MemProcFS

C 3,062 373 Updated Oct 24, 2024

Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on multiple such images

Python 48 4 Updated Jul 2, 2023

Google Filestream Forensic Tool

Python 16 1 Updated Mar 10, 2022

A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.

Python 109 15 Updated Jan 26, 2022