dfir-dd / dionysos
Scanner for certain IoCs
☆11Updated 3 weeks ago
Alternatives and similar repositories for dionysos:
Users that are interested in dionysos are comparing it to the libraries listed below
- Manage Your Large Team of Consultants☆11Updated 3 weeks ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆74Updated this week
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Updated 2 years ago
- Windows file metadata / forensic tool.☆18Updated 5 months ago
- ShellSweeping the evil.☆52Updated 8 months ago
- Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!☆45Updated 4 months ago
- ☆65Updated this week
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆76Updated last year
- Jupyter Notebooks for Cyber Threat Intelligence☆36Updated last year
- ☆21Updated 4 months ago
- Python based CLI for MalwareBazaar☆36Updated 3 months ago
- lnk_parser is a full rust implementation to parse windows LNK files☆16Updated last month
- ☆20Updated last year
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆58Updated 2 years ago
- Modular malware analysis artifact collection and correlation framework☆53Updated 9 months ago
- A specification and style guide for YARA rules☆45Updated last year
- ☆28Updated this week
- Sample evtx files to use for testing hayabusa detection rules☆48Updated 3 months ago
- ☆33Updated 2 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆23Updated 3 years ago
- A web scraper to create MISP events and reports☆14Updated 2 years ago
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆37Updated last year
- Validates Sigma rules using the JSON schema☆16Updated 11 months ago
- ESXi Cyber Security Incident Response Script☆23Updated 5 months ago
- Digital Forensics Artifacts Knowledge Base☆77Updated 9 months ago
- ☆18Updated 2 years ago
- Python library to query various sources of threat intelligence for data on domains, file hashes, and IP addresses.☆31Updated last year
- User Feedback Space of #MitreAssistant☆37Updated last year
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆68Updated last year
- This repository contains OpenIOC rules to aid in hunting for indicators of compromise and TTPs focused on Advanced Persistent Threat grou…☆23Updated last year