Tools for Incident Response and Malware Analysis
☆11Feb 9, 2025Updated last year
Alternatives and similar repositories for DFIR-Malware-Analysis
Users that are interested in DFIR-Malware-Analysis are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Browse Windows Recycle Bin from E01 forensic images with Explorer-style interface. Parse $I/$R artifacts, view deleted files in original …☆18Dec 16, 2025Updated 7 months ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆16Jul 6, 2026Updated 2 weeks ago
- A GUI tool used to parse Sysmon log and display as process tree☆18Mar 21, 2026Updated 4 months ago
- Volume Shadow Copy Explorer☆15Nov 23, 2025Updated 8 months ago
- AI modular structure that provides automation-based attack and penetration☆14May 10, 2024Updated 2 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Identifies metadata of .NET binary files.☆21Apr 3, 2024Updated 2 years ago
- ☆23Apr 1, 2026Updated 3 months ago
- Quick ESXi Log Parser☆33Updated this week
- Go bindings for libnotify -- Create and update OS notifications in linux☆13Jul 22, 2024Updated 2 years ago
- An implementation of EndpointSecurity on the 5BSD kernel.☆16May 31, 2026Updated last month
- Cyber Analytics Platform and Examination System (CAPES) Project Page☆14Feb 1, 2022Updated 4 years ago
- Linux Programming Interface Kerrisk☆12Jan 11, 2019Updated 7 years ago
- CyberChef update scripts in PowerShell & Bash☆18Apr 22, 2024Updated 2 years ago
- Tools and scripts to deploy and manage OpenRelik instances☆17Mar 23, 2026Updated 4 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- The most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl)…☆31Jul 16, 2026Updated last week
- Triage automation tool☆22Updated this week
- A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.☆164Apr 6, 2025Updated last year
- Forensic Browser History Analyzer - Cross-platform browser history extractor (Chrome, Firefox, IE/Edge, Brave, Opera, Vivaldi)☆35Apr 11, 2026Updated 3 months ago
- VTC - Velociraptor Timeline Creator☆19May 15, 2024Updated 2 years ago
- A tool for fetching DFIR and other GitHub tools.☆29Aug 2, 2025Updated 11 months ago
- Comprehensive adversary emulation tool for security testing on Google Cloud Platform (GCP) environments.☆14Jun 14, 2024Updated 2 years ago
- Dissectify — macOS Forensic Analysis Toolkit. Collection health validation, 61 artifact parsers, XLSX export, and Velociraptor collector …☆50Jun 1, 2026Updated last month
- ☆177Aug 25, 2023Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆18Jul 13, 2026Updated last week
- Turn a supported list of filetypes (e.g. .docx) into a markdown structured text file. Also optionally defangs indicators and extract text…☆12Updated this week
- This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you selec…☆32Feb 22, 2025Updated last year
- ioc2rpz webgui☆17Jul 7, 2026Updated 2 weeks ago
- ☆35Dec 6, 2023Updated 2 years ago
- A list of generic Red Team "backlog" items that most Red Teams would do to prep for operations or to work on during down time☆16Jul 28, 2025Updated 11 months ago
- Helm chart deploys Latest Apache NiFi in a Kubernetes cluster☆16Nov 9, 2025Updated 8 months ago
- ☆30Oct 18, 2025Updated 9 months ago
- Python script for carving Bitlocker VMK keys☆26Feb 4, 2026Updated 5 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆54Updated this week
- Track incidents, map attack paths, collaborate in real time, and generate AI-powered reports — all in one place.☆21May 13, 2026Updated 2 months ago
- Detects and reports malicious clipboard content (PowerShell, mshta, etc.) on any page, with user alerts.☆16Oct 5, 2025Updated 9 months ago
- Linux Persistence Detection, Hunting and Artifact Collection script☆24Updated this week
- Incident Response automation scripts☆16Sep 5, 2025Updated 10 months ago
- VANET using OMNET++, SUMO, Open Street Map, Veins, Inet☆11May 14, 2024Updated 2 years ago
- This command-line interface (CLI) application provides a robust and reliable way to download media from your Snapchat memories export fil…☆21Nov 27, 2025Updated 7 months ago