ForensicITGuy / handy-cti
Resources I've found useful for my CTI work
☆12Updated last year
Alternatives and similar repositories for handy-cti:
Users that are interested in handy-cti are comparing it to the libraries listed below
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆115Updated last year
- CSIRT Jump Bag☆27Updated 9 months ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆111Updated last year
- Notes on managing and coordinating the response to major cyber incidents☆39Updated 4 years ago
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆35Updated last month
- User Feedback Space of #MitreAssistant☆37Updated last year
- Collection of scripts provided for public use☆34Updated 2 months ago
- MISP-STIX-Converter - Python library to handle the conversion between MISP and STIX formats☆53Updated 3 weeks ago
- ☆32Updated 3 months ago
- Python library for threat intelligence☆82Updated 2 weeks ago
- ☆86Updated 11 months ago
- Digital Forensics Artifacts Knowledge Base☆76Updated 8 months ago
- Remote access and Antivirus Logging Database☆43Updated 9 months ago
- Repository of public reference frameworks for the DFIR community.☆112Updated last year
- A collection of tips for using MISP.☆74Updated last month
- A PowerShell incident response script for quick triage☆78Updated 2 years ago
- ☆4Updated 3 months ago
- Full of public notes and Utilities☆95Updated 2 months ago
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆20Updated 3 months ago
- Library of threat hunts to get any user started!☆41Updated 4 years ago
- Logbook for Digital Forensics and Incident Response☆50Updated 6 months ago
- A new Cyber Threat Intelligence Capability Maturity Model (CTI-CMM) to empower your team and create lasting value. Inspired by Industry N…☆24Updated 3 weeks ago
- Random notes collected on the intertubes relating to DFIR☆32Updated last year
- Open Threat-Informed Detection Engineering☆34Updated 3 weeks ago
- Azure function to insert MISP data in to Azure Sentinel☆31Updated 2 years ago
- Supporting materials for my "Intelligence-Led Adversarial Threat Modelling with VECTR" workshop☆57Updated 2 weeks ago
- My Jupyter Notebooks☆36Updated 9 months ago
- Repository for SPEED SIEM Use Case Framework☆52Updated 4 years ago
- An open source platform to support analysts to organise their case and tasks☆65Updated this week
- BlackBerry Threat Research & Intelligence☆96Updated last year