meta data for this page
Tools
SIEM
Network
IR
-
- remote artefact collection and administration
-
- Collaborative Incident Response Platform
Commandline
-
- Parse Windows Event Logs
-
- Analysis of file systems and images
-
- Parses windows event logs or sysmon/linux
Windows GUI
-
- TZworks, yet another registry utility
-
- TZWorks, USB parser
-
- tcpview, resmon,
Malware Analysis
Data Collection
-
- Collect artefacts on Win, Linux and MacOS
-
- Unix Artefacts Collector
-
- ntfswalk, gena (gui)
- Scripts