Data Volátil 3.0 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374
  1. https://medium.com/falconforce/sysmon-11-dns-improvements-and-filedelete-events-7a74f17ca842 : Encontrar archivos borrados en Active Directory
  2. https://github.com/JPCERTCC/SysmonSearch
  3. Cloud Forensics: https://dftimewolf.readthedocs.io/en/latest/user-manual.html
  4. PowerShell RAM Capture: https://www.kitploit.com/2022/11/collect-memorydump-automated-creation.html
  5. Ransowmare Dattabase>>>https://www.ransom-db.com/
  6. Incident Response en Windows> https://learn.microsoft.com/en-us/sysinternals/downloads/security-utilities
  7. Ransowmare Response: https://medium.com/swlh/detecting-and-responding-to-ransomware-attacks-by-using-free-tools-1873c8510a9e
  8. Memoria Volátil:
  9. ....https://www.volatilityfoundation.org/
  10. ....https://fireeye.market/
  11. ....https://www.magnetforensics.com/resources/magnet-process-capture/
  12. ....https://www.magnetforensics.com/resources/magnet-ram-capture/
  13. Discos encriptados:
  14. ....https://www.magnetforensics.com/resources/encrypted-disk-detector/
  15. ....http://www.disk-editor.org/index.html
  16. ....https://mh-nexus.de/en/hxd/
  17. Ubicar historial y Strings en navegadores(Decriptores):
  18. ----------------------
  19. DB Browser for SQLite (Open “.sqlite” files) https://sqlitebrowser.org/
  20. Nirsoft Web Browsers Tools (Contains a multitude of tools to open cache files, cookies and history data)https://www.nirsoft.net/web_browser_tools.html
  21. BrowsingHistoryView .... https://www.nirsoft.net/utils/browsing_history_view.html
  22. ESEDatabaseView...https://www.nirsoft.net/utils/ese_database_view.html
  23. Session History Scrounger for Firefox (Opens “.jsonlz4” files)....https://www.jeffersonscher.com/ffu/scrounger.html
  24. Sysinternals Strings....https://docs.microsoft.com/en-us/sysinternals/downloads/strings
  25. OS Forensics....https://www.osforensics.com/
  26. Magnet IEF (Internet Evidence Finder)....https://www.magnetforensics.com/products/magnet-ief/
  27. Browser History Viewer....https://www.foxtonforensics.com/browser-history-viewer/
  28. Browser History Examiner (Free Trial)....https://www.foxtonforensics.com/browser-history-examiner/
  29. Hindsight.....https://github.com/obsidianforensics/hindsight
  30. libsedb (Library to access the Extensible Storage Engine (ESE) Database File (EDB) format)....https://github.com/libyal/libesedb
  31. Web Browser Addons View (Use to view installed extensions and addons)....https://www.nirsoft.net/utils/web_browser_addons_view.html
  32. The LaZagne Project....https://github.com/AlessandroZ/LaZagne
  33. firepwd.py (open source tool to decrypt Mozilla protected passwords)....
  34. Firefox Search Engine Extractor (Open ‘search.json.mozlz4’ files)...https://www.jeffersonscher.com/ffu/searchjson.html
  35. Firefox Bookmark Backup Reader/Decompressor (Open ‘ jsonlz4’ files)....https://www.jeffersonscher.com/ffu/bookbackreader.html
  36. IOS Tools:
  37. -----https://github.com/jfarley248/MEAT
  38. MAC OS Tools:
  39. ----Framework: https://www.kitploit.com/2020/04/crescendo-swift-based-real-time-event.html