fsfang / DFIR-ToolkitLinks
This is a repo for cybersecurity analyst collecting artifacts in a incident response case.
☆19Updated 11 months ago
Alternatives and similar repositories for DFIR-Toolkit
Users that are interested in DFIR-Toolkit are comparing it to the libraries listed below
Sorting:
- ☆160Updated 2 years ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆252Updated 3 months ago
- yara detection rules for hunting with the threathunting-keywords project☆157Updated 9 months ago
- ShellSweeping the evil.☆181Updated last year
- PowerShell Script Analyzer☆70Updated 2 years ago
- Initial triage of Windows Event logs☆106Updated last year
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆143Updated last week
- Automating EDR Testing with reference to MITRE ATTACK via Cobalt Strike [Purple Team].☆155Updated 2 years ago
- RegRipper4.0☆81Updated 2 months ago
- ☆32Updated last year
- A collection of tools, scripts and personal research☆155Updated last week
- CarbonBlack EDR detection rules and response actions☆73Updated last year
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆105Updated 3 years ago
- Contains compiled binaries of Volatility☆37Updated 8 months ago
- Linux Evidence Acquisition Framework☆119Updated last year
- A running list of Windows sources and the related event ids.☆19Updated 2 years ago
- https://lolad-project.github.io/☆84Updated last year
- ☆54Updated last week
- IOC Collection 2022☆57Updated 2 years ago
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆17Updated 2 years ago
- Configuration Extractors for Malware☆123Updated 9 months ago
- Volatility, on Docker 🐳☆41Updated 2 months ago
- Simulation of Akira Ransomware with Invoke-AtomicTest☆18Updated last year
- ☆194Updated 2 years ago
- Linux Baseline and Forensic Triage Tool - BETA☆57Updated 3 years ago
- Rapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence…☆76Updated last month
- Packet captures of malicious traffic for analysis using Wireshark☆64Updated 2 years ago
- Advanced Bash script designed for conducting digital forensics on Linux systems☆144Updated last year
- A collection of tools and detections for the Sliver C2 Frameworj☆133Updated 2 years ago
- Free training course offered at Hack Space Con 2023☆138Updated 2 years ago