defender-detectionhistory-parser

Forensic parser

A Python-based tool for parsing and analyzing Windows Defender's DetectionHistory forensic artifact.

A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.

GitHub

110 stars
8 watching
15 forks
Language: Python
last commit: over 4 years ago

Related projects:

RepositoryDescriptionStars
dissectmalware/officeforensictoolsA Python-based collection of tools for gathering forensic information from Office documents26
sekoialab/fastir_collectorA tool for collecting and analyzing Windows system artefacts on live systems507
ydkhatri/mac_aptA digital forensics tool for analyzing macOS and iOS systems790
msuhanov/dfir_ntfsA digital forensics tool for parsing and analyzing NTFS/FAT file systems.196
cylance/pypackerdetectAn executable detection tool using PE parsing and machine learning signatures to identify packed samples.30
travisfoley/dfirtriageA digital forensic tool designed to gather and analyze data from Windows-based systems in incident response scenarios.335
pjrinaldi/wombatforensicsA multi-threaded GUI forensic analysis tool for Linux48
flo354/iosforensicA tool to aid in forensic analysis of iOS devices63
ownsecurity/fastir_artifactsA tool for collecting forensic artifacts from live hosts across multiple operating systems.160
joxeankoret/pyewA command-line tool for analyzing malware and disassembling binary files386
idiom/pftriageTool to analyze files during malware analysis and triage by extracting properties and detecting malicious indicators.77
hashlookup/hashlookup-forensic-analyserAnalyze digital evidence by searching for files against a large public hash database and generating reports on findings.126
patois/xrayTool for filtering and highlighting decompiler output based on regular expressions125
uqcyber/coldpressAutomates malware analysis workflow by extracting features and indicators of compromise from malicious files using various tools and libraries.16
sh3llyr/yarascanparserA tool to parse JSON output from Yara Scan Service's malware analysis and extract relevant information for rule optimization.11