Skip to content

ndr-repo/investigators-toolkit

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

16 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

investigators-toolkit

Tools for threat hunting & cyber incident response

scheduledExecHunter

Automated threat hunting for executable files in scheduled tasks

  • Discovers Scheduled Tasks with file execution instructions
  • Displays location of executable file
  • Creates SHA256 file checksum hash
  • Searches each hash on Open Threat Exchange
  • Displays results of each hash searched on OTX
image

Automated threat hunting for TCP listener files

  • Discovers running files listening on TCP ports
  • Displays location of file
  • Creates SHA256 file checksum hash
  • Searches each hash on Open Threat Exchange
  • Displays results of each hash searched on OTX

EVTX file discovery in System32

  • Discovers event log files for external processing (ie: DeepBlueCLI )
  • Orders event log files by size & last write time

About

Tools for threat hunting & cyber incident response

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published