incident response scripts
☆18Mar 4, 2019Updated 6 years ago
Alternatives and similar repositories for ir_scripts
Users that are interested in ir_scripts are comparing it to the libraries listed below
Sorting:
- A completely unsupported set of scripts used in SANS FOR572, Advanced Network Forensics and Analysis☆28Aug 6, 2025Updated 6 months ago
- PowerShell version of Fail2Ban☆13Oct 10, 2019Updated 6 years ago
- Some dfir stuff☆31Jan 12, 2022Updated 4 years ago
- The scrip will help you to find some values info for the user that you need as DFIR☆16Nov 3, 2022Updated 3 years ago
- macOS Artifact Intelligence Tool☆13Apr 30, 2019Updated 6 years ago
- Invoke-LiveResponse☆150Feb 22, 2022Updated 4 years ago
- ☆39Feb 12, 2020Updated 6 years ago
- Tony's collection of powershell scripts, typically geared toward cybersec☆35Jan 16, 2026Updated last month
- Knowledge base of analytics designed to cover threats based on MITRE's ATT&CK.☆23Dec 13, 2018Updated 7 years ago
- A set of Bash scripts that allows you to repeatably collect and compare baseline audit data from Linux and Windows systems☆20Oct 19, 2013Updated 12 years ago
- MISP trainings, threat intel and information sharing training materials with source code☆424Dec 17, 2025Updated 2 months ago
- A script to create and assign SOP tasks into the cases☆20Aug 16, 2020Updated 5 years ago
- Threat Mitigation Strategies☆28Feb 18, 2026Updated last week
- Searches For Threat Hunting and Security Analytics☆238Mar 26, 2025Updated 11 months ago
- Specifications used in the MISP project including MISP core format☆53Jan 7, 2026Updated last month
- ☆77Jun 25, 2019Updated 6 years ago
- Random scripts posted for my blog at http://aka.ms/goateepfe☆25Mar 30, 2017Updated 8 years ago
- This package allows the use of a custom Elastalert Alert which creates alerts with observables in TheHive using TheHive4Py.☆26May 18, 2021Updated 4 years ago
- This repository was created to aid in the deployment/maintenance of the Sysmon service on a large number of computers.☆83Mar 20, 2023Updated 2 years ago
- ☆50Aug 30, 2020Updated 5 years ago
- ☆18Apr 16, 2015Updated 10 years ago
- Blazescan is a linux webserver malware scanning and incident response tool, with built in support for cPanel servers, but will run on any…☆60Nov 10, 2018Updated 7 years ago
- WLEAPP is an open source project that aims to parse Windows OS artifacts for the purpose of triage analysis.☆32Nov 16, 2023Updated 2 years ago
- No-Script Automation Tool☆56Aug 6, 2018Updated 7 years ago
- A collection of typical false positive indicators☆56Dec 5, 2020Updated 5 years ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆55Jul 1, 2022Updated 3 years ago
- ☆56Jun 12, 2021Updated 4 years ago
- ☆53Mar 4, 2019Updated 6 years ago
- Evolving directions on building the best Open Source Forensics VM☆161Jul 5, 2018Updated 7 years ago
- Detection Ideas & Rules repository.☆178Sep 10, 2021Updated 4 years ago
- PowerShell scripts for running Magnet RESPONSE forensic collection tool in large enterprises.☆30Jan 9, 2025Updated last year
- Incident Response Scripts☆30Mar 1, 2020Updated 5 years ago
- automate your MISP installs☆68Jul 10, 2020Updated 5 years ago
- Powering Up Incident Response with Power-Response☆63Mar 5, 2020Updated 5 years ago
- Parser fo macOS/iOS FSEvents Logs☆43May 6, 2024Updated last year
- Recipes for GCHQ's CyberChef Web App☆39Nov 15, 2018Updated 7 years ago
- ☆10Aug 4, 2020Updated 5 years ago
- A PowerShell Module which recreates netstat.exe functionality☆35Aug 30, 2018Updated 7 years ago
- ☆33Oct 16, 2025Updated 4 months ago