An Incident Response tool that visualizes historic process execution evidence (based on Event ID 4688 - Process Creation Event) in a tree view.
☆60Jan 30, 2018Updated 8 years ago
Alternatives and similar repositories for HistoricProcessTree
Users that are interested in HistoricProcessTree are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Edited version of Lee Christensen's Get-NetworkConnection which includes timestamp for each network connection☆36Mar 14, 2018Updated 8 years ago
- An Incident Response tool to extract console command history and screen output buffer☆42Jan 11, 2018Updated 8 years ago
- Server for receiving autorun data from the clients☆13Sep 26, 2017Updated 8 years ago
- PowerShell Utilities for Security Situational Awareness☆13Jan 10, 2017Updated 9 years ago
- Some dfir stuff☆31Jan 12, 2022Updated 4 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆24Jul 9, 2021Updated 5 years ago
- Query and report user logons relations from MS Windows Security Events☆241Aug 9, 2018Updated 8 years ago
- Golang Parser for Microsoft Event Logs☆109Jun 12, 2026Updated last month
- Passive DNS server interface compliant to "Common Output Format"☆10Sep 19, 2016Updated 9 years ago
- A Compiler from Sigma rules to VQL☆19May 18, 2026Updated 2 months ago
- Konrads' Pen-Ultimate (Windows) Log File Parser☆14Dec 27, 2025Updated 7 months ago
- Yara Scanner For IMAP Feeds and saved Streams☆28Nov 5, 2019Updated 6 years ago
- Automated Memory Forensic☆34Jul 18, 2018Updated 8 years ago
- Triage automation for suspect URLs☆13Jul 23, 2019Updated 7 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Signature engine for all your logs☆172Nov 13, 2023Updated 2 years ago
- Checks observables/ioc in TheHive/Cortex against the MISP warningslists☆14Dec 27, 2017Updated 8 years ago
- Basic demo for Hidden Treasure talk.☆49Nov 4, 2017Updated 8 years ago
- Epimitheus is a tool that uses graphical database Neo4j for Windows Events visualization.☆19Mar 13, 2022Updated 4 years ago
- Tools for the Computer Incident Response Team☆152Apr 17, 2017Updated 9 years ago
- This is a repository from Adam Swan and I's presentation on Windows Logs Zero 2 Hero.☆22Jan 30, 2018Updated 8 years ago
- Various scrips☆12Oct 19, 2022Updated 3 years ago
- Simple Distributed IOC Scanner☆12Jul 27, 2015Updated 11 years ago
- Splunk app for Threat hunting☆15Nov 15, 2018Updated 7 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Ponmocup Indicators of Compromise☆10Feb 4, 2016Updated 10 years ago
- Reconstruct process trees from event logs☆148Aug 12, 2020Updated 5 years ago
- Virus names generator☆28Feb 10, 2015Updated 11 years ago
- IR-Tools - PowerShell tools for IR☆130Jul 10, 2017Updated 9 years ago
- This repository is a curated list of pro bono incident response entities.☆21Jun 21, 2023Updated 3 years ago
- Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research☆52Mar 16, 2018Updated 8 years ago
- PowerGRR is an API client library in PowerShell working on Windows, Linux and macOS for GRR automation and scripting.☆57Mar 18, 2022Updated 4 years ago
- Draugnet is a lightweight, open-source tool for anonymous cyber threat reporting. Built for the MISP ecosystem, it lets users submit and …☆21Jul 8, 2026Updated last month
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆43Sep 21, 2023Updated 2 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Triaging Windows event logs based on SANS Poster☆50Nov 22, 2025Updated 8 months ago
- Auxiliary scripts for Incident Response with ELK☆11Oct 7, 2015Updated 10 years ago
- A free incident response management and documentation workbook☆25Nov 13, 2018Updated 7 years ago
- Windows 10 Live Information viewer☆40Jan 27, 2022Updated 4 years ago
- Allows you to quickly query a Windows machine for RAM artifacts☆219Jul 17, 2020Updated 6 years ago
- ☆317Aug 14, 2020Updated 5 years ago
- Scripts and code referenced in CrowdStrike blog posts☆342Nov 13, 2019Updated 6 years ago