☆22Aug 29, 2024Updated last year
Alternatives and similar repositories for TheDFIRThing
Users that are interested in TheDFIRThing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆107Mar 12, 2026Updated last week
- Sigma rules converted for direct use with Zircolite☆14Mar 16, 2026Updated last week
- Search Index Database Reporter☆131Oct 28, 2025Updated 4 months ago
- ☆14Oct 24, 2024Updated last year
- Contains compiled binaries of Volatility☆36May 18, 2025Updated 10 months ago
- A DFIR tool to analyze artifacts on macOS☆35Jan 18, 2021Updated 5 years ago
- USN Journal full path builder☆67Sep 16, 2024Updated last year
- Incident Response Methodologies (IRM), also called Incident Playbook, based on the work done by the CERT Societe General☆24Dec 16, 2021Updated 4 years ago
- Hunt the windows Registry automatically using VQL☆14Jan 6, 2026Updated 2 months ago
- A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts☆79Oct 20, 2025Updated 5 months ago
- A simple python script to generate nested folders based on user input. The script will also name and place a template report document and…☆11Jun 19, 2025Updated 9 months ago
- A tool for fetching DFIR and other GitHub tools.☆26Aug 2, 2025Updated 7 months ago
- A Heroku-based web honeypot that can be used to create and monitor fake HTTP endpoints (i.e. honeytokens).☆65Apr 24, 2019Updated 6 years ago
- A python script for easy static analysis and automatic signature generation of malware.☆12Sep 30, 2013Updated 12 years ago
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆120Oct 8, 2023Updated 2 years ago
- Windows Forensic Environment (WinFE) - based on WinPE☆40Mar 16, 2023Updated 3 years ago
- Windows Event Log "Microsoft-Windows-Partition%4Diagnostic.evtx" parser and devices' VSNs extractor.☆20Nov 28, 2023Updated 2 years ago
- Hunt for SQLite files used by various applications☆30Mar 1, 2026Updated 3 weeks ago
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆581Dec 6, 2025Updated 3 months ago
- Reimplementation of libdetectcoll in Go☆19Mar 6, 2017Updated 9 years ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆45Mar 13, 2026Updated last week
- Collection of scripts provided for public use☆41Feb 4, 2026Updated last month
- FOR508 Index - GCFA☆24May 19, 2018Updated 7 years ago
- CLI tools for forensic investigation of Windows artifacts☆349Jul 21, 2025Updated 8 months ago
- Can you pay the ransom in your country?☆14Dec 18, 2023Updated 2 years ago
- DFIR notebooks GCIH Gold project, paper☆12Apr 30, 2015Updated 10 years ago
- /ˈhäjˌpäj/ "a confused mixture."☆13Mar 17, 2026Updated last week
- Legacy Sigma Tools (sigmac etc.)☆16May 7, 2023Updated 2 years ago
- Sophos Central PowerShell module☆11Jul 11, 2023Updated 2 years ago
- PyVelociraptor contains the python bindings for the Velociraptor API.☆21Feb 11, 2026Updated last month
- Modular command-line threat hunting tool & framework.☆17Jul 20, 2020Updated 5 years ago
- L.I.A.M is an open source case management system for digital forensics labs. Law-Enforcement Investigations and Asset Management☆13Jul 4, 2025Updated 8 months ago
- ☆35Oct 20, 2024Updated last year
- This is a tutorial for a data-secure home surveillance system with notifications to mobile devices.☆13Mar 14, 2022Updated 4 years ago
- A suite of Volatility 3 plugins for memory forensics of Docker containers☆18Jan 10, 2024Updated 2 years ago
- Run Velociraptor on Security Onion☆41Jul 27, 2022Updated 3 years ago
- Automatically create iSCSI targets for all drives except for a boot device☆25May 23, 2025Updated 10 months ago
- Converts Sigma detection rules to a Splunk alert configuration.☆12Jul 1, 2021Updated 4 years ago
- Epimitheus is a tool that uses graphical database Neo4j for Windows Events visualization.☆19Mar 13, 2022Updated 4 years ago