TGViewer
EsecurityCo EsecurityCo @esecurityco · 2.72K subscribers
Post #3252 1.11K

Forwarded from cissp (Alireza Ghahrood)

Videos
• The Future of Incident Response - Presented by Bruce Schneier at OWASP AppSecUSA 2015.

Windows Evidence Collection
• AChoir - Framework/scripting tool to standardize and simplify the process of scripting live acquisition utilities for Windows.
• Crowd Response - Lightweight Windows console application designed to aid in the gathering of system information for incident response and security engagements. It features numerous modules and output formats.
• DFIR ORC - DFIR ORC is a collection of specialized tools dedicated to reliably parse and collect critical artifacts such as the MFT, registry hives or event logs. DFIR ORC collects data, but does not analyze it: it is not meant to triage machines. It provides a forensically relevant snapshot of machines running Microsoft Windows. The code can be found on GitHub.
• FastIR Collector - Tool that collects different artifacts on live Windows systems and records the results in csv files. With the analyses of these artifacts, an early compromise can be detected.
• Fibratus - Tool for exploration and tracing of the Windows kernel.
• Hoarder - Collecting the most valuable artifacts for forensics or incident response investigations.
• IREC - All-in-one IR Evidence Collector which captures RAM Image, $MFT, EventLogs, WMI Scripts, Registry Hives, System Restore Points and much more. It is FREE, lightning fast and easy to use.
• Invoke-LiveResponse - Invoke-LiveResponse is a live response tool for targeted collection.
• IOC Finder - Free tool from Mandiant for collecting host system data and reporting the presence of Indicators of Compromise (IOCs). Support for Windows only. No longer maintained. Only fully supported up to Windows 7 / Windows Server 2008 R2.
• IRTriage - Incident Response Triage - Windows Evidence Collection for Forensic Analysis.
• KAPE - Kroll Artifact Parser and Extractor (KAPE) by Eric Zimmerman. A triage tool that finds the most prevalent digital artifacts and then parses them quickly. Great and thorough when time is of the essence.
• LOKI - Free IR scanner for scanning endpoint with yara rules and other indicators(IOCs).
• MEERKAT - PowerShell-based triage and threat hunting for Windows.
• Panorama - Fast incident overview on live Windows systems.
• PowerForensics - Live disk forensics platform, using PowerShell.
• PSRecon - PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained locally.
• RegRipper - Open source tool, written in Perl, for extracting/parsing information (keys, values, data) from the Registry and presenting it for analysis
YouTube OWASP AppSecUSA 2014 - Keynote: Bruce Schneier - The Future of Incident Response Live from AppSecUSA 2014 in Denver http://2014.appsecusa.org/ Thursday, September 18 • 8:00am - 9:00am Keynote: Bruce Schneier - The Future of Incident Response Network attacks are inevitable. Protection and detection can only take you so far, and response…
More from @esecurityco
  1. May 29, 2025⛔️فقط ۳ ظرفیت باقی است⛔️ دوره Red Team Sans 565 شروع قطعی دوره : 19 خرداد زمان : دوشنبه ها…
  2. May 19, 2025تو دوره memory_Forensic که برای یکی از سازمان ها برگزار میکنم ، گفتم: 💯 مموری فارنزیک دقی…
  3. May 7, 2025🚀 شروع دوره ویژه: هوش مصنوعی برای سازمان‌ها 🎯 جلسه اول رایگان + دسترسی به گروه خصوصی هوش…
  4. May 2, 2025📌 گوگل ابزار کاربردی NotebookLM رو ارتقا داده و حالا علاوه بر انگلیسی، این ابزار میتونه ب…
  5. Apr 28, 2025گوگل از مدل امنیتی جدید خود رونمایی کرد: Sec-Gemini v1! در تاریخ ۴ آوریل ۲۰۲۵، گوگل به طور…
  6. Apr 18, 2025دوره کاربردی و فشرده هوش مصنوعی در خدمت سازمان‌ها تحول دیجیتال، بدون نیاز به دانش فنی! 📍…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →