diff --git a/README.md b/README.md index 8ae68ed..257bff9 100644 --- a/README.md +++ b/README.md @@ -569,6 +569,10 @@ This repository is created as an online bookmark for useful links, resources and fireeye/ARDvark ARDvark parses the Apple Remote Desktop (ARD) files to pull out application usage, user activity, and filesystem listings. + + fireeye/SilkETW + SilkETW & SilkService are flexible C# wrappers for ETW, they are meant to abstract away the complexities of ETW and give people a simple interface to perform research and introspection. + ForensicArtifacts/artifacts Digital Forensics Artifact Repository