binalyze / dfir-labLinks
☆10Updated 6 months ago
Alternatives and similar repositories for dfir-lab
Users that are interested in dfir-lab are comparing it to the libraries listed below
Sorting:
- ☆22Updated 2 years ago
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆68Updated 2 years ago
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 4 years ago
- Simple Script to Help You Find All Files Has Been Modified, Accessed, and Created In A Range Time.☆27Updated 3 years ago
- Sigma Engine implementation in TypeScript☆28Updated 2 years ago
- This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports☆79Updated 2 weeks ago
- my MSTICpy practice and custom tools repository☆11Updated 9 months ago
- Open Source Cyber Threat Intelligence Feed Collector☆17Updated 4 years ago
- Linux Baseline and Forensic Triage Tool - BETA☆57Updated 3 years ago
- ☆22Updated 3 years ago
- Library of threat hunts to get any user started!☆48Updated 5 years ago
- Jupyter Notebooks for Cyber Threat Intelligence☆35Updated 2 years ago
- IOC Data Obtained From Karakurt Hacking Team's Internal Infrastructure☆34Updated 3 years ago
- A MITRE ATT&CK Lookup Tool☆46Updated last year
- Threat Hunt Investigation Methodology and Procedure☆15Updated 3 years ago
- ☆28Updated 3 months ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆42Updated 2 years ago
- The Threat Actor Profile Guide for CTI Analysts☆116Updated 2 years ago
- Domain Connectivity Analysis Tools to analyze aggregate connectivity patterns across a set of domains during security investigations☆46Updated 4 years ago
- Thor Artifacts for Velociraptor☆19Updated 2 months ago
- IOC Stream and Command and Control Database Containing Command and Control (C2) Servers Detected Daily by ThreatMon.☆69Updated 2 years ago
- Track progress and keep notes while working through likethecoins' CTI Self Study Plan☆29Updated 3 years ago
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆27Updated 3 years ago
- The Chupacabra case study was created by the ADEO dfir team due to the lack of resources and applications in the digital forensics field.…☆23Updated 3 years ago
- ATLAS - Malware Analysis Description☆21Updated 2 years ago
- Actively hunt for attacker infrastructure by filtering Shodan results with URLScan data.☆63Updated last year
- Scripts and tools accompanying HP Threat Research blog posts and reports.☆50Updated last year
- A repository for tracking events related to the MOVEit Transfer Cl0p Campaign☆71Updated 2 years ago
- Simple PowerShell script to enable process scanning with Yara.☆98Updated 3 years ago
- CarbonBlack EDR detection rules and response actions☆73Updated last year