HackTheBox Sherlocks Writeups
GitHub
  • Introduction
  • Tools
  • DFIR - Digital Forensics and Incident Response
    • DFIR
      • Unit42
      • Brutus
  • SOC - Security Operations Center
    • SOC
  • Campaign
    • Campaign
  • Cloud
    • Cloud
  • Threat Intelligence
    • Threat Intelligence
  • Malware Analysis
    • Malware Analysis
  • About
    • GitHub
Powered by GitBook
On this page

Was this helpful?

Edit on GitHub

Tools

在 Sherlocks 挑战过程中,使用以下工具可以更好的帮助你进行分析。

PreviousIntroductionNextDFIR

Last updated 1 year ago

Was this helpful?

工具
描述
标签

Volatility 2.6 是一个开源的数字取证工具,专门用于分析内存转储文件 - Linux 可执行文件

[linux binary file] [DFIR]

Volatility 2.6 是一个开源的数字取证工具,专门用于分析内存转储文件 - Windows 可执行文件

[windows binary file] [DFIR]

C# based evtx parser with lots of extras

[evtx] [DFIR]

Utilities for Sysmon (Sysmon View)

[sysmon] [DFIR]

AWS CloudTrail log files merge

[python] [splunk] [cloud]

一个快速搭建 splunk 的 docker-compose 文件

[docker-compose] [splunk] [log]

volatility_2.6_lin64_standalone
volatility_2.6_win64_standalone.exe
EvtxECmd
SysmonTools
aws_cloudtrail_analysis
splunk-docker-compose.yml