forensicsim
ccl_chrome_indexeddb
forensicsim | ccl_chrome_indexeddb | |
---|---|---|
1 | 1 | |
57 | 109 | |
- | - | |
9.0 | 6.8 | |
3 months ago | 3 months ago | |
Python | Python | |
MIT License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
forensicsim
-
3rd party app to read MS Teams?
I’ve used https://github.com/lxndrblz/forensicsim as a stand-alone and it worked well. Also works as an autopsy plugin but haven’t used it.
ccl_chrome_indexeddb
-
Leveldb File Forensics
I would suggest using https://github.com/cclgroupltd/ccl_chrome_indexeddb/blob/master/dump_leveldb.py - it's worked well for me exploring different LevelDB stores I've run across. The syntax is like python dump_leveldb.py "input directory", where "input directory" is the folder containing all the LevelDB files (.ldb, .sst, .log, LOG, LOCK, MANIFEST-*, etc). It outputs everything in a CSV ( and includes deleted values, which can be interesting).
What are some alternatives?
teams-for-linux - Unofficial Microsoft Teams for Linux client
Leveldb-py - Leveldb Dumper/Viewer
APT-Hunter - APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
ChromeController - Comprehensive wrapper and execution manager for the Chrome browser using the Chrome Debugging Protocol.
teams-call - Shell script to detect when you're in a Microsoft Teams Call. Supports Linux and macOS.
LevelDB - LevelDB is a fast key-value storage library written at Google that provides an ordered mapping from string keys to string values.
LevelDBViewer - A Java program provides ablities to access & edit leveldb database
selenium-python-helium - Lighter web automation for Python [Moved to: https://github.com/mherrmann/helium]
DFIRMindMaps - A repository of DFIR-related Mind Maps geared towards the visual learners!
Loki - Loki - Simple IOC and YARA Scanner