AndrewRathbun / DFIRArtifactMuseumLinks
The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.
☆638Updated 2 months ago
Alternatives and similar repositories for DFIRArtifactMuseum
Users that are interested in DFIRArtifactMuseum are comparing it to the libraries listed below
Sorting:
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆640Updated last year
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆547Updated 3 years ago
- The official repo for a project involving a crowdsourced DFIR book. The main purpose of this book is to give anyone interested an opportu…☆217Updated 3 weeks ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆294Updated this week
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆408Updated 2 months ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆607Updated last month
- ☆513Updated last year
- The Volatility Collaborative GUI☆264Updated last week
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆342Updated last month
- Harness the power of Splunk for your investigations☆148Updated 3 months ago
- An analytical challenge created to test junior analysts looking to try performing proactive and reactive cyber threat intelligence.☆201Updated last year
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆186Updated 2 months ago
- CyLR - Live Response Collection Tool☆703Updated 3 years ago
- Documentation and scripts to properly enable Windows event logs.☆653Updated 3 months ago
- Awesome list of keywords and artifacts for Threat Hunting sessions☆627Updated 5 months ago
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆805Updated 3 weeks ago
- Rules generated from our investigations.☆203Updated 7 months ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆771Updated 9 months ago
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆956Updated 2 years ago
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆217Updated 2 months ago
- A python script developed to process Windows memory images based on triage type.☆263Updated 2 years ago
- Signatures and IoCs from public Volexity blog posts.☆361Updated last month
- CTI Blueprints is a free suite of templates and tools that helps Cyber Threat Intelligence analysts create high-quality, actionable repor…☆276Updated 10 months ago
- Repository of attack and defensive information for Business Email Compromise investigations☆273Updated 8 months ago
- 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system☆302Updated 8 months ago
- Map tracking ransomware, by OCD World Watch team☆482Updated this week
- Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).☆799Updated last week
- Indexes for SANS Courses and GIAC Certifications☆275Updated last year
- Jupyter Notebooks for the Blue Team☆145Updated 10 months ago
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆518Updated 2 weeks ago