Hands-on projects for beginners to learn and practice Windows forensics and essential cybersecurity skills
-
Updated
Jun 29, 2024
Hands-on projects for beginners to learn and practice Windows forensics and essential cybersecurity skills
Cross-platform registry browser for raw Windows registry files
Windows forensics Engine
ExeSpy is a cross-platform PE viewer for EXE and DLL files
Vault of Windows Registry forensic artifacts
Rust DFIR tool that massively parses cross-platform evidence, even deleted logs, into a lateral movement timeline and graph database.
A comprehensive MCP server for Windows digital forensics on KALI Linux
A DFIR Incident Response AI bot using local Ollama LLM to derrive automated findings from logs
Tools and Techniques for Digital Forensics and Incident Response
Command Spy is a utility for monitoring the command line arguments of new processes on Windows. Made for CCDC.
Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.
Point it at disk + memory evidence; get a correlated, ATT&CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps, parses NTFS/registry/EVTX/prefetch/LNK/SRUM/browser/Amcache + memory (processes, netstat, injection), correlates into a DuckDB super-timeline, scans threat-intel, and reports.
A comprehensive repository for CyberOps documentation, Blue Team playbooks, and open-source forensic tools like Cerberus and Chimera.
Python module for forensic analysis of Windows shortcuts (LNK files). You can install this package using pip install lnkanalyser
Valhuntir Windows forensic tool execution via MCP
Search artifact paths, build collection scripts, and convert Sigma rules. All in one place.
Ferramenta pericial desenvolvida para agilizar a triagem inicial e análise de evidências digitais, além de permitir a Aquisição Forense (Bit-a-bit) de unidades lógicas e físicas. Um "canivete suíço" offline e portátil que faz o trabalho pesado de extração de dados de forma rápida, segura e em lote.
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
Practical labs, case studies, and investigation notes for CHFI v11 — covering digital forensics, malware forensics, incident response, evidence collection, and analysis tools.
Useful tools for (not only) digital forensics
To associate your repository with the windows-forensics topic, visit your repo's landing page and select "manage topics."