From 7bc2418d3e86d29c90542ef937a1bc9bd180cb6d Mon Sep 17 00:00:00 2001 From: pe3zx Date: Thu, 2 Jan 2020 17:24:03 +0700 Subject: [PATCH] Add: FireEye/SilkETW --- README.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/README.md b/README.md index 8ae68ed..257bff9 100644 --- a/README.md +++ b/README.md @@ -569,6 +569,10 @@ This repository is created as an online bookmark for useful links, resources and fireeye/ARDvark ARDvark parses the Apple Remote Desktop (ARD) files to pull out application usage, user activity, and filesystem listings. + + fireeye/SilkETW + SilkETW & SilkService are flexible C# wrappers for ETW, they are meant to abstract away the complexities of ETW and give people a simple interface to perform research and introspection. + ForensicArtifacts/artifacts Digital Forensics Artifact Repository