') + ')', 'gi');
if (regex.test(text)) {
found = true;
var frag = document.createDocumentFragment();
var parts = text.split(regex);
parts.forEach(function(part, i) {
if (i % 2 === 0) {
frag.appendChild(document.createTextNode(part));
} else {
var span = document.createElement('span');
span.className = 'userscript-highlight';
span.textContent = part;
frag.appendChild(span);
}
});
node.parentNode.replaceChild(frag, node);
}
});
} else if (node.nodeType === 1 && node.childNodes) { // element
var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];
if (!skipTags.includes(node.tagName)) {
Array.from(node.childNodes).forEach(highlight);
}
}
}
highlight(document.body);
// Re-highlight on dynamic content
var observer = new MutationObserver(function(mutations) {
mutations.forEach(function(m) {
m.addedNodes.forEach(function(node) {
if (node.nodeType === 1 || node.nodeType === 3) highlight(node);
});
});
});
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); }
})();
(function(){
try {
var __m = "*";
var __re = new RegExp('^' + ".*" + ', 'i');
if (__m === '*' || __re.test(location.href)) {
// Strip utm_, fbclid, gclid, etc. from all links on page
(function() {
var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',
'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',
'ref', 'ref_src', 'source', 'medium', 'campaign'];
function cleanUrl(url) {
try {
var u = new URL(url, window.location.origin);
var changed = false;
trackingParams.forEach(function(p) {
if (u.searchParams.has(p)) {
u.searchParams.delete(p);
changed = true;
}
});
return changed ? u.toString() : url;
} catch (e) {
return url;
}
}
function cleanLinks() {
document.querySelectorAll('a[href]').forEach(function(a) {
var clean = cleanUrl(a.href);
if (clean !== a.href) a.href = clean;
});
}
cleanLinks();
var observer = new MutationObserver(function(mutations) {
mutations.forEach(function(m) {
m.addedNodes.forEach(function(node) {
if (node.nodeType === 1) {
if (node.tagName === 'A') cleanLinks();
node.querySelectorAll('a[href]').forEach(function(a) {
var clean = cleanUrl(a.href);
if (clean !== a.href) a.href = clean;
});
}
});
});
});
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); }
})();
(function(){
try {
var __m = "youtube.com";
var __re = new RegExp('^' + "youtube\\.com" + ', 'i');
if (__m === '*' || __re.test(location.href)) {
// Auto-enable theater mode on YouTube
(function() {
function tryTheater() {
var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]');
if (btn && !btn.classList.contains('activated')) {
btn.click();
}
}
// Try immediately
tryTheater();
// Try after navigation (SPA)
var lastUrl = location.href;
setInterval(function() {
if (location.href !== lastUrl) {
lastUrl = location.href;
setTimeout(tryTheater, 500);
}
}, 1000);
// Also try on player load
var observer = new MutationObserver(tryTheater);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); }
})();
(function(){
try {
var __m = "*";
var __re = new RegExp('^' + ".*" + ', 'i');
if (__m === '*' || __re.test(location.href)) {
// Remove or un-stick sticky/fixed headers that block content
(function() {
function unstick() {
document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) {
if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {
el.style.position = 'static';
el.style.top = 'auto';
el.style.zIndex = 'auto';
}
});
}
unstick();
var observer = new MutationObserver(unstick);
observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });
})();
}
} catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); }
})();
})();
dfir-dd · GitHub
A team of incident responders and forensic analysts, currently working at BDO Cyber Security in Dresden.
Need to contact us? Send a mail to info@dfir-dd.de .
Tool What does it do ? DFIR Toolkit Collection of CLI tools for Windows forensic analysis dionysos Scanner for various IoCs, esp. yara-based Dissect Triage A binary to collect triage data from Windows Systems, based on dissect Kirby Parse several forensic artifacts from a windows (triage) image, based on dissect
Popular repositories
Loading
CLI tools for forensic investigation of Windows artifacts
Rust
355
30
Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents
54
5
Scanner for certain IoCs
Rust
11
2
Windows registry parser library build upon BinRead
Rust
7
3
A script to parse several forensic artifacts of given windows (triage) images, using dissect
Python
2
Custom Artifacts for Rapid7 Velociraptor Software
2
Repositories
Showing 10 of 12 repositories kirby
Public
A script to parse several forensic artifacts of given windows (triage) images, using dissect
dfir-dd/kirby's past year of commit activity Python
2 GPL-3.0
0
0
0
Updated Feb 5, 2026 dfir-dd/dfir-scripts's past year of commit activity Shell
0 GPL-3.0
1
2
0
Updated Oct 1, 2025 nt-hive2
Public archive
Windows registry parser library build upon BinRead
dfir-dd/nt-hive2's past year of commit activity Rust
7 GPL-3.0
3
2
0
Updated Jul 21, 2025 dfir-toolkit
Public archive
CLI tools for forensic investigation of Windows artifacts
dfir-dd/dfir-toolkit's past year of commit activity Rust
355 GPL-3.0
30
2
1
Updated Jul 21, 2025 packer
Public
Packer Templates to build vagrant base boxes
dfir-dd/packer's past year of commit activity Shell
1
0
0
0
Updated May 23, 2025 dionysos
Public
Scanner for certain IoCs
dfir-dd/dionysos's past year of commit activity Rust
11 GPL-3.0
2
1
0
Updated Jan 29, 2025 pr
Public
Public relations stuff
dfir-dd/pr's past year of commit activity
0
0
0
0
Updated Jul 30, 2024 dfir-dd/dissect-triage's past year of commit activity Python
1
0
0
0
Updated May 31, 2024 dfir-dd/.github's past year of commit activity
0
0
0
0
Updated May 21, 2024 dfir-dd/incident-response-playbooks's past year of commit activity
54 CC-BY-SA-4.0
5
0
0
Updated Apr 25, 2024
You can’t perform that action at this time.