AndrewRathbun / DFIRArtifactMuseumLinks
The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.
☆609Updated 6 months ago
Alternatives and similar repositories for DFIRArtifactMuseum
Users that are interested in DFIRArtifactMuseum are comparing it to the libraries listed below
Sorting:
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆630Updated last year
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆379Updated 8 months ago
- ☆513Updated 11 months ago
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆531Updated 3 years ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆272Updated last week
- The official repo for a project involving a crowdsourced DFIR book. The main purpose of this book is to give anyone interested an opportu…☆215Updated 7 months ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆588Updated 8 months ago
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆763Updated last week
- CyLR - Live Response Collection Tool☆686Updated 3 years ago
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆330Updated 4 months ago
- Awesome list of keywords and artifacts for Threat Hunting sessions☆603Updated last month
- Documentation and scripts to properly enable Windows event logs.☆628Updated last year
- An analytical challenge created to test junior analysts looking to try performing proactive and reactive cyber threat intelligence.☆199Updated last year
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆742Updated 5 months ago
- Rules generated from our investigations.☆198Updated 2 months ago
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆174Updated 9 months ago
- The Volatility Collaborative GUI☆251Updated this week
- Repository of attack and defensive information for Business Email Compromise investigations☆261Updated 4 months ago
- Harness the power of Splunk for your investigations☆129Updated 2 weeks ago
- CTI Blueprints is a free suite of templates and tools that helps Cyber Threat Intelligence analysts create high-quality, actionable repor…☆265Updated 5 months ago
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆208Updated 2 weeks ago
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆938Updated last year
- Windows Malware Investigation Scripts & Docs☆84Updated 10 months ago
- Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!☆384Updated last year
- A python script developed to process Windows memory images based on triage type.☆265Updated last year
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆671Updated last month
- Get all my software☆169Updated 3 months ago
- Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).☆753Updated last week
- A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.☆714Updated 3 months ago
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,114Updated 2 weeks ago