diff --git a/README.md b/README.md index f9fdca5..37e929a 100644 --- a/README.md +++ b/README.md @@ -1741,6 +1741,10 @@ This repository is created as an online bookmark for useful links, resources and jklepsercyber/defender-detectionhistory-parser A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables. + + joeavanzato/Trawler + PowerShell script to help Incident Responders discover adversary persistence mechanisms. + JPCERTCC/LogonTracer Investigate malicious Windows logon by visualizing and analyzing Windows event log