Skip to content

timetology/tools

Repository files navigation

Awesome Lists of Tools

Tools

Host Forensics

Windows

Evidence of Execution

Zimmerman

Triage

$MFT

$USNJRNL - $USN Journal

Program Execution

Registry

RDP

RDP Bitmap Cache

Shellbags

Notes

http://windowsir.blogspot.com/2012/08/shellbag-analysis.html https://www.4n6k.com/2013/12/shellbags-forensics-addressing.html https://volatility-labs.blogspot.com/2012/09/movp-32-shellbags-in-memory-setregtime.html

LNK

Timeliner

Yara

Memory

Logs

Windows User Access Logs (UAL)

C:\Windows\System32\LogFiles\SUM

Browsers

Chrome

Notes
Locations
Default Locations:
Windows XP:	\[userdir\]\Local Settings\Application Data\Google\Chrome\User Data
Vista/7/8/10:	\[userdir\]\AppData\Local\Google\Chrome\User Data
Linux:	\[userdir\]/.config/google-chrome
OSX/macOS:	\[userdir\]/Library/Application Support/Google/Chrome/Default
iOS:	\Applications\com.google.chrome.ios\Library\Application Support\Google\Chrome
Android:	/userdata/data/com.android.chrome/app_chrome
Links

Brave

Locations
Default Locations:
Vista/7/8/10:	\[userdir\]\AppData\Roaming\brave
Linux:	\[userdir\]/.config/brave
OSX/macOS:	\[userdir\]/Library/Application Support/brave
Links

Bits

Locations

%%ALLUSERSPROFILE%%\Microsoft\Network\Downloader\*
C:\ProgramData\Microsoft\Network\Downloader\*

Win10+

C:\ProgramData\Microsoft\Network\Downloader\qmgr.db

Pre-Win10

C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat

Parsers

Malware Analysis

Dynamic Analysis

Static Analysis

Peristence

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published