Scripts to integrate DFIR-IRIS, MISP and TimeSketch
☆37Feb 2, 2022Updated 4 years ago
Alternatives and similar repositories for dfir-iris-misp-timesketch
Users that are interested in dfir-iris-misp-timesketch are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the hos…☆32May 21, 2026Updated 3 months ago
- CSIRT Jump Bag☆27Apr 25, 2024Updated 2 years ago
- Mass Triage Tools☆20Mar 10, 2026Updated 5 months ago
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆122Oct 8, 2023Updated 2 years ago
- macOS Artifact Intelligence Tool☆13Apr 30, 2019Updated 7 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Open source training materials for law-enforcement and organisations interested in DFIR.☆64May 29, 2026Updated 3 months ago
- ☆33Feb 26, 2022Updated 4 years ago
- Rip Raw is a small tool to analyse the memory of compromised Linux systems.☆133Jan 31, 2022Updated 4 years ago
- Different tools, koen.vanimpe@cudeso.be☆139Jul 21, 2025Updated last year
- A suite of Volatility 3 plugins for memory forensics of Docker containers☆18Jan 10, 2024Updated 2 years ago
- Python client for DFIR-IRIS☆29Aug 19, 2024Updated 2 years ago
- Sigma rules converted for direct use with Zircolite☆15Updated this week
- Volatility plugin to search for all Autostart Extensibility Points (AESPs)☆10Jun 13, 2026Updated 2 months ago
- A script to assist in processing forensic RAM captures for malware triage☆26Feb 4, 2021Updated 5 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆38Jul 18, 2024Updated 2 years ago
- Tool to read EVTX files including SYSMON and convert to JSON, MISP Objects and Graph stream☆12Oct 29, 2020Updated 5 years ago
- evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.☆159Nov 30, 2021Updated 4 years ago
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆120Jan 26, 2022Updated 4 years ago