diff --git a/README.md b/README.md index 28144d9..8f6fc1e 100644 --- a/README.md +++ b/README.md @@ -1545,6 +1545,10 @@ This repository is created as an online bookmark for useful links, resources and jimtin/IRCoreForensicFramework Powershell 7 (Powershell Core)/ C# cross platform forensic framework. Built by incident responders for incident responders. + + jklepsercyber/defender-detectionhistory-parser + A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables. + JPCERTCC/LogonTracer Investigate malicious Windows logon by visualizing and analyzing Windows event log