Scripts to integrate DFIR-IRIS, MISP and TimeSketch
☆37Feb 2, 2022Updated 4 years ago
Alternatives and similar repositories for dfir-iris-misp-timesketch
Users that are interested in dfir-iris-misp-timesketch are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the hos…☆32May 21, 2026Updated 4 months ago
- CSIRT Jump Bag☆27Apr 25, 2024Updated 2 years ago
- Mass Triage Tools☆20Sep 9, 2026Updated 2 weeks ago
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆122Oct 8, 2023Updated 2 years ago
- macOS Artifact Intelligence Tool☆13Apr 30, 2019Updated 7 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Open source training materials for law-enforcement and organisations interested in DFIR.☆64May 29, 2026Updated 3 months ago
- ☆33Feb 26, 2022Updated 4 years ago
- Rip Raw is a small tool to analyse the memory of compromised Linux systems.☆133Jan 31, 2022Updated 4 years ago
- Different tools, koen.vanimpe@cudeso.be☆139Jul 21, 2025Updated last year
- A suite of Volatility 3 plugins for memory forensics of Docker containers☆19Jan 10, 2024Updated 2 years ago
- Python client for DFIR-IRIS☆31Aug 19, 2024Updated 2 years ago
- Sigma rules converted for direct use with Zircolite☆15Updated this week
- Volatility plugin to search for all Autostart Extensibility Points (AESPs)☆10Jun 13, 2026Updated 3 months ago
- A script to assist in processing forensic RAM captures for malware triage☆26Feb 4, 2021Updated 5 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Tool to read EVTX files including SYSMON and convert to JSON, MISP Objects and Graph stream☆12Oct 29, 2020Updated 5 years ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆38Jul 18, 2024Updated 2 years ago
- evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.☆159Nov 30, 2021Updated 4 years ago
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆120Jan 26, 2022Updated 4 years ago
- ☆34Oct 25, 2021Updated 4 years ago
- ☆21Oct 17, 2025Updated 11 months ago
- Construct triage artifact based on rules☆16Updated this week
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆75Jan 18, 2022Updated 4 years ago
- Automation script to download JSON MISP files from a SFTP server and import them via API to a MISP instance.☆15May 12, 2023Updated 3 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- shell script to create an image and perform initial examination on a drive☆15Feb 28, 2020Updated 6 years ago
- A simple python script to generate nested folders based on user input. The script will also name and place a template report document and…☆12May 6, 2026Updated 4 months ago
- A command-line tool for parsing Windows Master File Table ($MFT) and importing the results into Elasticsearch.☆12Sep 18, 2026Updated last week
- Presentation Slides and Resources☆16Jun 12, 2024Updated 2 years ago
- Jupyter Notebooks for Digital Forensics & Incident Response☆10Nov 23, 2021Updated 4 years ago
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆21Oct 25, 2023Updated 2 years ago
- Common Exercise Format - CEXF☆11Aug 15, 2024Updated 2 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆24Jul 9, 2021Updated 5 years ago
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆553Sep 2, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- CocktailParty is a data broker system based on phoenix framework☆23Apr 23, 2025Updated last year
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆14Jun 27, 2023Updated 3 years ago
- The Volatility Collaborative GUI☆277Updated this week
- A python script developed to process Windows memory images based on triage type.☆268Nov 25, 2023Updated 2 years ago
- Lua plugin to extract data from Wireshark and convert it into MISP format☆50Oct 23, 2023Updated 2 years ago
- PowerShell module for Office 365 and Azure log collection☆284Sep 22, 2025Updated last year
- A Modular MWDB Utility to Collect Fresh Malware Samples☆33May 17, 2021Updated 5 years ago