☆22Aug 29, 2024Updated last year
Alternatives and similar repositories for TheDFIRThing
Users that are interested in TheDFIRThing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆108Mar 12, 2026Updated 3 months ago
- Sigma rules converted for direct use with Zircolite☆15Updated this week
- Search Index Database Reporter☆139Oct 28, 2025Updated 8 months ago
- ☆15Oct 24, 2024Updated last year
- Contains compiled binaries of Volatility☆36May 18, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A DFIR tool to analyze artifacts on macOS☆35Jan 18, 2021Updated 5 years ago
- USN Journal full path builder☆69Apr 16, 2026Updated 2 months ago
- Incident Response Methodologies (IRM), also called Incident Playbook, based on the work done by the CERT Societe General☆24Dec 16, 2021Updated 4 years ago
- A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts☆81Oct 20, 2025Updated 8 months ago
- A simple python script to generate nested folders based on user input. The script will also name and place a template report document and…☆12May 6, 2026Updated last month
- A tool for fetching DFIR and other GitHub tools.☆29Aug 2, 2025Updated 11 months ago
- Hunt the windows Registry automatically using VQL☆18May 4, 2026Updated 2 months ago
- Sigma detection rules for hunting with the threathunting-keywords project☆60Mar 2, 2025Updated last year
- A python script for easy static analysis and automatic signature generation of malware.☆12Sep 30, 2013Updated 12 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆122Oct 8, 2023Updated 2 years ago
- Windows Event Log "Microsoft-Windows-Partition%4Diagnostic.evtx" parser and devices' VSNs extractor.☆20Nov 28, 2023Updated 2 years ago
- Hunt for SQLite files used by various applications☆31Jun 17, 2026Updated 2 weeks ago
- Windows Forensic Environment (WinFE) - based on WinPE☆42Mar 16, 2023Updated 3 years ago
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆637Jun 20, 2026Updated 2 weeks ago
- Reimplementation of libdetectcoll in Go☆19Mar 6, 2017Updated 9 years ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆50Jun 3, 2026Updated last month
- Collection of scripts provided for public use☆43Jun 14, 2026Updated 2 weeks ago
- FOR508 Index - GCFA☆25May 19, 2018Updated 8 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Bash script for performing the logical acquisition of Apple Silicon Mac☆18Jun 21, 2024Updated 2 years ago
- CLI tools for forensic investigation of Windows artifacts☆354Jul 21, 2025Updated 11 months ago
- Can you pay the ransom in your country?☆14Dec 18, 2023Updated 2 years ago
- DFIR notebooks GCIH Gold project, paper☆12Apr 30, 2015Updated 11 years ago
- /ˈhäjˌpäj/ "a confused mixture."☆16Jun 1, 2026Updated last month
- Legacy Sigma Tools (sigmac etc.)☆17May 7, 2023Updated 3 years ago
- ☆74May 11, 2026Updated last month
- Sophos Central PowerShell module☆12Jul 11, 2023Updated 2 years ago
- L.I.A.M is an open source case management system for digital forensics labs. Law-Enforcement Investigations and Asset Management☆14Jul 4, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Modular command-line threat hunting tool & framework.☆17Jul 20, 2020Updated 5 years ago
- A cross platform forensic parser written in Rust!☆114Updated this week
- ☆35Oct 20, 2024Updated last year
- This is a tutorial for a data-secure home surveillance system with notifications to mobile devices.☆13Mar 14, 2022Updated 4 years ago
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆65Dec 21, 2022Updated 3 years ago
- A suite of Volatility 3 plugins for memory forensics of Docker containers☆18Jan 10, 2024Updated 2 years ago
- Run Velociraptor on Security Onion☆41Jul 27, 2022Updated 3 years ago