This Repository consists all Public Cheatsheets created by BlackPerl DFIR Content Team
☆20Oct 9, 2024Updated last year
Alternatives and similar repositories for IR-Cheatsheets
Users that are interested in IR-Cheatsheets are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆13Mar 28, 2026Updated 6 months ago
- Passivedns monitor implementation in Rust.☆12Apr 21, 2016Updated 10 years ago
- This Repository gives the best and possible strategies against hunting the ransomware☆26Aug 23, 2022Updated 4 years ago
- Threat Hunt Investigation Methodology and Procedure☆15Jul 11, 2022Updated 4 years ago
- A summary of the most abbreviations I encountered so far☆29Aug 20, 2026Updated last month
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A collection of useful, small python3 scripts for penetration testing/ethical hacking which I created over the years.☆10Aug 13, 2022Updated 4 years ago
- Menu for Thor scanner lite☆20Oct 24, 2025Updated 11 months ago
- The Enhanced MITRE ATT&CK® Coverage Tracker is an Excel tool for SOCs to measure and improve detection coverage of cyber threats. It simp…☆36Nov 13, 2025Updated 10 months ago
- KQL Sentinel and Defender Detection and Hunting Queries.☆16Aug 17, 2026Updated last month
- reverse engineered and improved BSQLi script from Coffinxp☆14Aug 30, 2024Updated 2 years ago
- ☆17Jul 23, 2026Updated 2 months ago
- Sharing Threat Hunting runbooks☆27Jul 5, 2019Updated 7 years ago
- This tool can gather a lot of info without any defender alerts. It is useful for Penetration testers, SOC Analysts, System administrators…☆30Aug 25, 2026Updated last month
- Takajō (鷹匠) is a Hayabusa results analyzer.☆166Jul 11, 2026Updated 2 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Have you ever wanted to search a link or IP address on multiple OSINT pages at once?☆67Jul 7, 2025Updated last year
- Quick & dirty script to get info on a file from online resources (VirusTotal, Team Cymru, Shadow Server etc.)☆30Jun 24, 2014Updated 12 years ago
- Notes for the CRTO exam☆10May 22, 2022Updated 4 years ago
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- CarbonBlack EDR detection rules and response actions☆73Sep 10, 2024Updated 2 years ago
- yara detection rules for hunting with the threathunting-keywords project☆167May 11, 2025Updated last year
- Klara docker compose☆11May 19, 2020Updated 6 years ago
- API to use Cymru services☆27Dec 6, 2013Updated 12 years ago
- Sample evtx files to use for testing hayabusa detection rules☆71Nov 5, 2025Updated 10 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Explore the cyber realm with our concise collection! From Linux commands to XSS techniques, dive into incident response, bug bounty tips,…☆21Mar 6, 2024Updated 2 years ago
- About A comprehensive overview of FTK Imager, a forensic imaging tool for disk and memory acquisition, including usage guide☆36Oct 31, 2025Updated 10 months ago
- A collection of reports and case studies to understand the threat landscape for UK critical infrastructure☆39Jan 23, 2024Updated 2 years ago
- Winterfell hunt is a python script to perform auto threat hunting for malicious activities in windows OS based on collected data by winte…☆15Jul 23, 2020Updated 6 years ago
- Red Team Stored XSS SVG phishing-companion tool with the ability to serve a malicious login page, or clone an html page and implement cus…☆32Mar 31, 2023Updated 3 years ago
- Library of threat hunts to get any user started!☆51Sep 4, 2020Updated 6 years ago
- ☆32Mar 11, 2026Updated 6 months ago
- Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.☆16Oct 22, 2025Updated 11 months ago
- Automate forensic traige package collection and evidence parsing with KAPE and Crowdstrike☆15Mar 5, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- This config file will automatically convert a temporary Windows Sandbox environment into a Flare VM for malware analysis.☆10Jan 3, 2025Updated last year
- This repository provides a comprehensive Digital Footprint Checklist to help individuals manage their online presence and enhance privacy…☆18Dec 25, 2024Updated last year
- A collaboration effort by the DFIR community to provide definitions (sometimes multiple) for common forensic terms!☆27Dec 1, 2022Updated 3 years ago
- ☆19Dec 23, 2024Updated last year
- ☆16Oct 24, 2024Updated last year
- Tools and scripts to deploy and manage OpenRelik instances☆17Mar 23, 2026Updated 6 months ago
- CLI tool written in Go to generate Canary Tokens from https://canarytokens.org☆13Aug 22, 2025Updated last year