☆22Aug 29, 2024Updated last year
Alternatives and similar repositories for TheDFIRThing
Users that are interested in TheDFIRThing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆108Mar 12, 2026Updated 3 months ago
- Sigma rules converted for direct use with Zircolite☆15Updated this week
- Search Index Database Reporter☆136Oct 28, 2025Updated 7 months ago
- ☆15Oct 24, 2024Updated last year
- Contains compiled binaries of Volatility☆36May 18, 2025Updated last year
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A DFIR tool to analyze artifacts on macOS☆35Jan 18, 2021Updated 5 years ago
- Incident Response Methodologies (IRM), also called Incident Playbook, based on the work done by the CERT Societe General☆24Dec 16, 2021Updated 4 years ago
- A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts☆81Oct 20, 2025Updated 7 months ago
- A simple python script to generate nested folders based on user input. The script will also name and place a template report document and…☆12May 6, 2026Updated last month
- A tool for fetching DFIR and other GitHub tools.☆29Aug 2, 2025Updated 10 months ago
- Hunt the windows Registry automatically using VQL☆17May 4, 2026Updated last month
- Sigma detection rules for hunting with the threathunting-keywords project☆60Mar 2, 2025Updated last year
- A Heroku-based web honeypot that can be used to create and monitor fake HTTP endpoints (i.e. honeytokens).☆65Apr 24, 2019Updated 7 years ago
- A python script for easy static analysis and automatic signature generation of malware.☆12Sep 30, 2013Updated 12 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆122Oct 8, 2023Updated 2 years ago
- Windows Event Log "Microsoft-Windows-Partition%4Diagnostic.evtx" parser and devices' VSNs extractor.☆20Nov 28, 2023Updated 2 years ago
- Hunt for SQLite files used by various applications☆31Mar 1, 2026Updated 3 months ago
- Windows Forensic Environment (WinFE) - based on WinPE☆41Mar 16, 2023Updated 3 years ago
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆630Jun 3, 2026Updated last week
- Reimplementation of libdetectcoll in Go☆19Mar 6, 2017Updated 9 years ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆49Jun 3, 2026Updated last week
- Collection of scripts provided for public use☆43May 19, 2026Updated 3 weeks ago
- FOR508 Index - GCFA☆25May 19, 2018Updated 8 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Bash script for performing the logical acquisition of Apple Silicon Mac☆18Jun 21, 2024Updated last year
- CLI tools for forensic investigation of Windows artifacts☆353Jul 21, 2025Updated 10 months ago
- Can you pay the ransom in your country?☆14Dec 18, 2023Updated 2 years ago
- DFIR notebooks GCIH Gold project, paper☆12Apr 30, 2015Updated 11 years ago
- /ˈhäjˌpäj/ "a confused mixture."☆15Jun 1, 2026Updated last week
- Legacy Sigma Tools (sigmac etc.)☆17May 7, 2023Updated 3 years ago
- ☆74May 11, 2026Updated last month
- Sophos Central PowerShell module☆12Jul 11, 2023Updated 2 years ago
- Modular command-line threat hunting tool & framework.☆17Jul 20, 2020Updated 5 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- L.I.A.M is an open source case management system for digital forensics labs. Law-Enforcement Investigations and Asset Management☆13Jul 4, 2025Updated 11 months ago
- A cross platform forensic parser written in Rust!☆113Updated this week
- ☆35Oct 20, 2024Updated last year
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆65Dec 21, 2022Updated 3 years ago
- This is a tutorial for a data-secure home surveillance system with notifications to mobile devices.☆13Mar 14, 2022Updated 4 years ago
- A suite of Volatility 3 plugins for memory forensics of Docker containers☆18Jan 10, 2024Updated 2 years ago
- Run Velociraptor on Security Onion☆41Jul 27, 2022Updated 3 years ago