incident response scripts
☆18Mar 4, 2019Updated 7 years ago
Alternatives and similar repositories for ir_scripts
Users that are interested in ir_scripts are comparing it to the libraries listed below
Sorting:
- PowerShell version of Fail2Ban☆13Oct 10, 2019Updated 6 years ago
- A completely unsupported set of scripts used in SANS FOR572, Advanced Network Forensics and Analysis☆28Aug 6, 2025Updated 7 months ago
- Invoke-LiveResponse☆150Feb 22, 2022Updated 4 years ago
- This repository was created to aid in the deployment/maintenance of the Sysmon service on a large number of computers.☆83Mar 20, 2023Updated 3 years ago
- Threat Mitigation Strategies☆28Feb 18, 2026Updated last month
- ☆39Feb 12, 2020Updated 6 years ago
- Searches For Threat Hunting and Security Analytics☆238Mar 26, 2025Updated 11 months ago
- A set of Bash scripts that allows you to repeatably collect and compare baseline audit data from Linux and Windows systems☆20Oct 19, 2013Updated 12 years ago
- A script to create and assign SOP tasks into the cases☆20Aug 16, 2020Updated 5 years ago
- Random scripts posted for my blog at http://aka.ms/goateepfe☆25Mar 30, 2017Updated 8 years ago
- Tony's collection of powershell scripts, typically geared toward cybersec☆35Jan 16, 2026Updated 2 months ago
- ☆53Mar 4, 2019Updated 7 years ago
- ☆50Aug 30, 2020Updated 5 years ago
- No-Script Automation Tool☆56Aug 6, 2018Updated 7 years ago
- Accompanying PowerShell Modules for DevSec Defense Presentation☆30Apr 15, 2018Updated 7 years ago
- macOS Artifact Intelligence Tool☆13Apr 30, 2019Updated 6 years ago
- SQL Server Inventory and Baselining using Powershell and SSRS☆14Dec 10, 2014Updated 11 years ago
- Build Windows 2012 SQL 2012 multi-subnet five node AG labs with one command using Hyper-V and DSC☆12Sep 3, 2024Updated last year
- Some dfir stuff☆31Jan 12, 2022Updated 4 years ago
- MISP trainings, threat intel and information sharing training materials with source code☆427Dec 17, 2025Updated 3 months ago
- WLEAPP is an open source project that aims to parse Windows OS artifacts for the purpose of triage analysis.☆32Nov 16, 2023Updated 2 years ago
- Powering Up Incident Response with Power-Response☆63Mar 5, 2020Updated 6 years ago
- This package allows the use of a custom Elastalert Alert which creates alerts with observables in TheHive using TheHive4Py.☆26May 18, 2021Updated 4 years ago
- ☆77Jun 25, 2019Updated 6 years ago
- Challenges for the TheManyHatsClub CTF☆11May 1, 2023Updated 2 years ago
- Script to enabled DNS Debug Logging across Domain Controllers in a Forest and then retrieve for analysis☆14May 27, 2016Updated 9 years ago
- ☆18Apr 16, 2015Updated 10 years ago
- PowerShell module used to interact with Dyn Managed DNS REST API☆12Jun 4, 2023Updated 2 years ago
- Blazescan is a linux webserver malware scanning and incident response tool, with built in support for cPanel servers, but will run on any…☆60Nov 10, 2018Updated 7 years ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆55Jul 1, 2022Updated 3 years ago
- Zac's assorted config files☆10Jan 11, 2017Updated 9 years ago
- Pushes Sysmon Configs☆90Jun 11, 2021Updated 4 years ago
- An attempt to simplify and customize error views☆17Feb 10, 2026Updated last month
- Evolving directions on building the best Open Source Forensics VM☆161Jul 5, 2018Updated 7 years ago
- Knowledge base of analytics designed to cover threats based on MITRE's ATT&CK.☆23Dec 13, 2018Updated 7 years ago
- ☆265Oct 25, 2025Updated 4 months ago
- PowerShell scripts for running Magnet RESPONSE forensic collection tool in large enterprises.☆31Jan 9, 2025Updated last year
- Log newly created WMI consumers and processes to the Windows Application event log☆124Feb 28, 2018Updated 8 years ago
- JIRA CLI☆20Sep 16, 2021Updated 4 years ago