AppCompatProcessor has been designed to extract additional value from enterprise-wide AppCompat / AmCache data beyond the classic stacking and grepping techniques. Note: Windows platform support has been temporarily removed (expect to see it back shortly though). Installation: OSX: You need Python 2.7+, libregf and pyregf (python bindings) from https://github.com/libyal/libregf -Option A Source distribution package from https://github.com/libyal/libregf/releases ./configure --enable-python && make sudo make install python setup.py build python setup.py install -Option B Direct from source git clone https://github.com/libyal/libregf.git cd libregf/ ./synclibs.sh ./autogen.sh ./configure --enable-python && make sudo make install python setup.py build python setup.py install The rest of the requirements you can handle with 'pip install -r requirements.txt'. Linux: You need Python 2.7+ and 'sudo pip install -r requirements.txt' should take care of everything for you. If you have issues with libregf or
This tool is not verified yet and doesn't have listed features.
Did you submit the verified tool? Sign in to add features.
Are you the author? Claim the tool by clicking the icon above. After claiming, you can add features.
Repository of Yara Rules created by TjNel.
A visualization tool for threat analysis that organizes APT campaign information and visualizes relations of IOC.
A list of most queried domains based on passive DNS usage across the Umbrella global network.
Open Source Intelligence solution for threat intelligence data enrichment and quick analysis of suspicious files or malware.
Amazon GuardDuty is a threat detection service for AWS accounts.
A repository of Yara signatures under the GNU-GPLv2 license for the cybersecurity community.