The Windows-RedTeam repository contains resources I have developed for Red Team exercises or Pentesting engagements in Windows environments.
-
Updated
Jan 2, 2020 - PowerShell
The Windows-RedTeam repository contains resources I have developed for Red Team exercises or Pentesting engagements in Windows environments.
TimeStomp-Detection A forensic analysis tool for detecting timestamp tampering in Windows systems. Automates metadata extraction and cross-referencing from NTFS MFT, ShimCache, Amcache, and $I30 entries. Outputs consolidated insights to help investigators identify timestomping artifacts efficiently.
Add a description, image, and links to the timestomp topic page so that developers can more easily learn about it.
To associate your repository with the timestomp topic, visit your repo's landing page and select "manage topics."