Skip to content

Instantly share code, notes, and snippets.

@raminfp
Created May 25, 2025 07:24
Show Gist options
  • Save raminfp/670612298d61fe449fc04f4886fa8b9b to your computer and use it in GitHub Desktop.
Save raminfp/670612298d61fe449fc04f4886fa8b9b to your computer and use it in GitHub Desktop.
System Information Collection:
https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer
Registry Artifacts :
https://www.majorgeeks.com/files/details/registryexplorer.html
File System & User Activity :
https://www.majorgeeks.com/files/details/usbdeview.html
https://www.nirsoft.net/utils/shadow_copy_view.html
User Activity
https://www.nirsoft.net/utils/browsing_history_view.html
https://github.com/EricZimmerman/JLECmd
Network Activity
https://learn.microsoft.com/en-us/sysinternals/downloads/tcpview
https://www.netresec.com/?page=NetworkMiner
Persistence Mechanisms:
https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
https://learn.microsoft.com/de-de/sysinternals/downloads/sysmon
Security & Authentication
https://learn.microsoft.com/de-de/sysinternals/downloads/logonsessions
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment