☆22Aug 29, 2024Updated last year
Alternatives and similar repositories for TheDFIRThing
Users that are interested in TheDFIRThing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆108Mar 12, 2026Updated last month
- Sigma rules converted for direct use with Zircolite☆14Updated this week
- Search Index Database Reporter☆134Oct 28, 2025Updated 5 months ago
- ☆14Oct 24, 2024Updated last year
- Contains compiled binaries of Volatility☆36May 18, 2025Updated 10 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A DFIR tool to analyze artifacts on macOS☆35Jan 18, 2021Updated 5 years ago
- USN Journal full path builder☆68Apr 4, 2026Updated last week
- Incident Response Methodologies (IRM), also called Incident Playbook, based on the work done by the CERT Societe General☆24Dec 16, 2021Updated 4 years ago
- A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts☆79Oct 20, 2025Updated 5 months ago
- A simple python script to generate nested folders based on user input. The script will also name and place a template report document and…☆12Jun 19, 2025Updated 9 months ago
- A tool for fetching DFIR and other GitHub tools.☆27Aug 2, 2025Updated 8 months ago
- Sigma detection rules for hunting with the threathunting-keywords project☆59Mar 2, 2025Updated last year
- Hunt the windows Registry automatically using VQL☆14Jan 6, 2026Updated 3 months ago
- A python script for easy static analysis and automatic signature generation of malware.☆12Sep 30, 2013Updated 12 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆121Oct 8, 2023Updated 2 years ago
- Windows Forensic Environment (WinFE) - based on WinPE☆40Mar 16, 2023Updated 3 years ago
- Hunt for SQLite files used by various applications☆31Mar 1, 2026Updated last month
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆583Dec 6, 2025Updated 4 months ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆47Apr 4, 2026Updated last week
- A Wiki containing guides to modding many different consumer electronic devices.☆18Jul 5, 2014Updated 11 years ago
- Collection of scripts provided for public use☆42Updated this week
- FOR508 Index - GCFA☆24May 19, 2018Updated 7 years ago
- CLI tools for forensic investigation of Windows artifacts☆350Jul 21, 2025Updated 8 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Bash script for performing the logical acquisition of Apple Silicon Mac☆17Jun 21, 2024Updated last year
- Can you pay the ransom in your country?☆14Dec 18, 2023Updated 2 years ago
- DFIR notebooks GCIH Gold project, paper☆12Apr 30, 2015Updated 10 years ago
- /ˈhäjˌpäj/ "a confused mixture."☆13Updated this week
- Legacy Sigma Tools (sigmac etc.)☆16May 7, 2023Updated 2 years ago
- ☆72Apr 7, 2026Updated last week
- Sophos Central PowerShell module☆11Jul 11, 2023Updated 2 years ago
- A cross platform forensic parser written in Rust!☆104Updated this week
- PyVelociraptor contains the python bindings for the Velociraptor API.☆21Updated this week
- Serverless GPU API endpoints on Runpod - Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Modular command-line threat hunting tool & framework.☆17Jul 20, 2020Updated 5 years ago
- ☆35Oct 20, 2024Updated last year
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆65Dec 21, 2022Updated 3 years ago
- This is a tutorial for a data-secure home surveillance system with notifications to mobile devices.☆13Mar 14, 2022Updated 4 years ago
- A suite of Volatility 3 plugins for memory forensics of Docker containers☆18Jan 10, 2024Updated 2 years ago
- Run Velociraptor on Security Onion☆41Jul 27, 2022Updated 3 years ago
- Automatically create iSCSI targets for all drives except for a boot device☆25May 23, 2025Updated 10 months ago