Andrew Rathbun

Results 12 repositories owned by Andrew Rathbun

DFIRMindMaps

486
Stars
67
Forks
Watchers

A repository of DFIR-related Mind Maps geared towards the visual learners!

DFIRArtifactMuseum

539
Stars
48
Forks
Watchers

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts...

Awesome-KAPE

146
Stars
15
Forks
Watchers

A curated list of KAPE-related resources

Anti-Forensics-VHDX

25
Stars
4
Forks
Watchers

A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. Please add a new issue if you have an idea for something to add....

DFIRPowerShellScripts

39
Stars
14
Forks
Watchers

Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!

DFIRRegex

77
Stars
9
Forks
Watchers

A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.

DirectoryOpus-DFIRConfig

28
Stars
2
Forks
Watchers

A config file that's curated for DFIR examiners with shortcuts to common Windows artifacts and settings enabled that help make your life easier with various file management tasks.

EventTranscript.db-Research

38
Stars
3
Forks
Watchers

A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.

KAPE-EZToolsAncillaryUpdater

53
Stars
5
Forks
Watchers

A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools

SANSGoldPaperResearch_FOR500_Rathbun

24
Stars
4
Forks
Watchers

A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.