dbissell6 / DFIR
This is a repository dedicated to the DFIR journey. Contains notes, reflections and links to tools.
☆62Updated this week
Alternatives and similar repositories for DFIR:
Users that are interested in DFIR are comparing it to the libraries listed below
- DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital For…☆174Updated 3 weeks ago
- A Python script for analyzing email files to extract IP addresses, URLs, headers, and attachments, with functionalities for defanging IPs…☆18Updated 4 months ago
- Some important DFIR Resources☆83Updated last year
- Welcome to Project KillChain, a comprehensive GitHub repository for Red and Blue Teams. This repository houses tools, scripts, technique…☆100Updated 6 months ago
- Completely Risky Active-Directory Simulation Hub☆99Updated last year
- ☆155Updated last year
- ☆34Updated last month
- Advanced Bash script designed for conducting digital forensics on Linux systems☆138Updated 10 months ago
- Regular Expressions List used in Digital Forensic Tasks☆82Updated last year
- Windows Malware Investigation Scripts & Docs☆74Updated 3 months ago
- LOLAPPS is a compendium of applications that can be used to carry out day-to-day exploitation.☆179Updated this week
- ThreatSeeker: Threat Hunting via Windows Event Logs☆118Updated last year
- A curated list of awesome LOLBins, GTFO projects, and similar 'Living Off the Land' security resources.☆140Updated 3 months ago
- autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat☆109Updated last year
- A specification and style guide for YARA rules☆45Updated last year
- A collection of CVEs weaponized by ransomware operators☆104Updated last month
- ☆165Updated 11 months ago
- Hands-on cybersecurity projects to enhance skills in phishing investigation, malware analysis, network intrusion detection, and DDoS atta…☆110Updated 8 months ago
- A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.☆151Updated 9 months ago
- Knowledge Management for Offensive Security Professionals Official Repository☆134Updated last month
- Creation of a laboratory for malware analysis in AWS☆93Updated 2 years ago
- Pythia is a versatile query format designed to facilitate the discovery of malicious infrastructure by seamlessly converting into the syn…☆31Updated 6 months ago
- The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders und…☆118Updated 10 months ago
- CarbonBlack EDR detection rules and response actions☆71Updated 5 months ago
- R3D SSH Hunter: The Ultimate SSH Key and Bad Guy Tracker☆12Updated 3 months ago
- 🧰 ESXi Testing Tookit is a command-line utility designed to help security teams test ESXi detections.☆68Updated last month
- ☆36Updated last month
- A repository of credential stealer formats☆193Updated 3 weeks ago