The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.
☆664Jul 14, 2026Updated 2 months ago
Alternatives and similar repositories for DFIRArtifactMuseum
Users that are interested in DFIRArtifactMuseum are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆665Jun 19, 2024Updated 2 years ago
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆205Oct 29, 2025Updated 10 months ago
- The official repo for a project involving a crowdsourced DFIR book. The main purpose of this book is to give anyone interested an opportu…☆221Dec 30, 2025Updated 8 months ago
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,461Sep 9, 2026Updated 2 weeks ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆736Aug 31, 2026Updated 3 weeks ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A python script developed to process Windows memory images based on triage type.☆268Nov 25, 2023Updated 2 years ago
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆346Dec 3, 2025Updated 9 months ago
- Documentation and scripts to properly enable Windows event logs.☆723Oct 3, 2025Updated 11 months ago
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,670Updated this week
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,361Sep 12, 2026Updated last week
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆553Sep 2, 2022Updated 4 years ago
- Digital Forensics artifact repository☆1,275Jul 31, 2026Updated last month
- Practical Windows Forensics Training☆784Feb 16, 2026Updated 7 months ago
- Event Tracing For Windows (ETW) Resources☆435Oct 30, 2025Updated 10 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆853Updated this week
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆1,083Oct 5, 2023Updated 2 years ago
- Carve file metadata from NTFS index ($I30) attributes☆73May 25, 2026Updated 4 months ago
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆878Sep 18, 2026Updated last week
- A curated list of KAPE-related resources☆192May 1, 2025Updated last year
- Windows Events Attack Samples☆2,628Jan 24, 2023Updated 3 years ago
- Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts…☆1,160Updated this week
- $MFT directory tree reconstruction & FILE record info☆331Oct 7, 2024Updated last year
- A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.☆851Jun 29, 2026Updated 2 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆70Sep 13, 2023Updated 3 years ago
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆870Jan 20, 2022Updated 4 years ago
- Digital Forensics Investigation Platform☆906Oct 12, 2024Updated last year
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆120Jan 26, 2022Updated 4 years ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆90Feb 9, 2025Updated last year
- DFIQ is a collection of investigative questions and the approaches for answering them☆316Mar 10, 2026Updated 6 months ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆642May 21, 2026Updated 4 months ago
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆964Updated this week
- Everything related to Linux Forensics☆729Jul 13, 2023Updated 3 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Blueteam operational triage registry hunting/forensic tool.☆148Sep 2, 2025Updated last year
- Awesome list of keywords and artifacts for Threat Hunting sessions☆673Aug 4, 2025Updated last year
- PowerShell module for Office 365 and Azure log collection☆284Sep 22, 2025Updated last year
- Repository of attack and defensive information for Business Email Compromise investigations☆281Jun 17, 2026Updated 3 months ago
- A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as …☆471Feb 18, 2026Updated 7 months ago
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆109Mar 12, 2026Updated 6 months ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆93Sep 14, 2026Updated last week