Triage automation tool
☆22Aug 19, 2026Updated last week
Alternatives and similar repositories for triager
Users that are interested in triager are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆23Apr 1, 2026Updated 4 months ago
- Automated n8n workflow for ransomware threat monitoring using ransomware.live API and Claude AI — companion to the SANS Ransomware Intell…☆22Apr 15, 2026Updated 4 months ago
- Browse Windows Recycle Bin from E01 forensic images with Explorer-style interface. Parse $I/$R artifacts, view deleted files in original …☆18Dec 16, 2025Updated 8 months ago
- Quick ESXi Log Parser☆33Jul 21, 2026Updated last month
- A comprehensive PowerShell toolkit for RDP forensics analysis, tracking connection attempts, authentication, sessions, and logoffs across…☆18Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆70Jan 8, 2026Updated 7 months ago
- A GUI tool used to parse Sysmon log and display as process tree☆18Mar 21, 2026Updated 5 months ago
- An AWS CloudTrail exported logs analyzer tool☆21Jul 26, 2026Updated last month
- The most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl)…☆31Jul 28, 2026Updated last month
- Neural network RDP cache reconstruction tool☆34May 21, 2026Updated 3 months ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆16Jul 6, 2026Updated last month
- A lightweight tool to view, search and analyze registry hives☆20Aug 13, 2026Updated 2 weeks ago
- Tools for Incident Response and Malware Analysis☆11Feb 9, 2025Updated last year
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆49Jul 20, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!☆53Jan 9, 2026Updated 7 months ago
- Forensic Browser History Analyzer - Cross-platform browser history extractor (Chrome, Firefox, IE/Edge, Brave, Opera, Vivaldi)☆38Aug 7, 2026Updated 3 weeks ago
- A tool for fetching DFIR and other GitHub tools.☆29Aug 2, 2025Updated last year
- Dissectify — macOS Forensic Analysis Toolkit. Collection health validation, 61 artifact parsers, XLSX export, and Velociraptor collector …☆51Aug 17, 2026Updated last week
- Forensic analysis of already-acquired WhatsApp Android databases - browse every chat exactly like the WhatsApp home screen, plus 30 foren…☆55May 9, 2026Updated 3 months ago
- Tools and scripts to deploy and manage OpenRelik instances☆17Mar 23, 2026Updated 5 months ago
- This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you selec…☆32Feb 22, 2025Updated last year
- ☆24Aug 16, 2026Updated last week
- Single-file desktop GUI for searching, browsing, and analyzing SQLite databases. Python + tkinter. No install required.☆24Apr 25, 2026Updated 4 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- An example ISMS created with Claude for a fictious organisation.☆21Apr 3, 2026Updated 4 months ago
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆35Jun 5, 2026Updated 2 months ago
- Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.☆40May 22, 2026Updated 3 months ago
- Just a vault template to help someone on the certificate.☆21Sep 3, 2025Updated 11 months ago
- A DFIR Incident Response AI bot using local Ollama LLM to derrive automated findings from logs☆17Jan 17, 2026Updated 7 months ago
- Binary template for ReFS and LogFile for 010 Editor that parses, and decodes the internal structures of ReFS metadata and log records☆16Apr 1, 2024Updated 2 years ago
- A Windows Event Log MCP☆49Aug 25, 2025Updated last year
- ☆30Feb 12, 2026Updated 6 months ago
- Deep Packet Inspection • Traffic Forensics • Network Threat Detection☆56Feb 20, 2026Updated 6 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A CTI program management and production platform built around MISP☆35Aug 14, 2026Updated 2 weeks ago
- Linux Memory Forensics Framework That Transforms Memory Dumps Into a Navigable Filesystem☆201Jul 4, 2026Updated last month
- Regexplore is a Volatility plugin designed to mimic the functionality of the Registry Explorer plugins in EZsuite☆18Mar 31, 2023Updated 3 years ago
- A collection of PowerShell scripts for analyzing macOS Forensic Artifacts☆34Mar 16, 2026Updated 5 months ago
- A GeoIP lookup utility utilizing ipinfo.io services.☆30Dec 1, 2023Updated 2 years ago
- Scripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE☆201Apr 1, 2026Updated 4 months ago
- A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV outp…☆334Feb 26, 2026Updated 6 months ago