Skip to content

Repository files navigation

investigators-toolkit

Tools for threat hunting & cyber incident response

scheduledExecHunter

Automated threat hunting for executable files in scheduled tasks

  • Discovers Scheduled Tasks with file execution instructions
  • Displays location of executable file
  • Creates SHA256 file checksum hash
  • Searches each hash on Open Threat Exchange
  • Displays results of each hash searched on OTX
image

Automated threat hunting for TCP listener files

  • Discovers running files listening on TCP ports
  • Displays location of file
  • Creates SHA256 file checksum hash
  • Searches each hash on Open Threat Exchange
  • Displays results of each hash searched on OTX

EVTX file discovery in System32

  • Discovers event log files for external processing (ie: DeepBlueCLI )
  • Orders event log files by size & last write time

About

Tools for threat hunting & cyber incident response

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages