gaurav-gogia / dftoolsLinks
A curated list of digital forensic tools.
☆22Updated 5 years ago
Alternatives and similar repositories for dftools
Users that are interested in dftools are comparing it to the libraries listed below
Sorting:
- PowerShell Memory Pulling script☆19Updated 10 years ago
- Home to the ActorTrackr source code☆30Updated 8 years ago
- A script to assist in processing forensic RAM captures for malware triage☆27Updated 4 years ago
- A few quick recipes for those that do not have much time during the day☆22Updated last year
- The "DFUR" Splunk application and data that was presented at the 2020 SANS DFIR Summit.☆12Updated 5 years ago
- This module installs and configures MISP (Malware Information Sharing Platform)☆13Updated 3 weeks ago
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated 2 years ago
- The ContactDB project was initiated to cover the need for a tool to maintain contacts for CSIRT teams☆37Updated 3 years ago
- Tools for parsing Forensic images☆41Updated 6 years ago
- A DFVFS Backed Forensic Viewer☆41Updated 5 years ago
- ☆33Updated 11 months ago
- Maltego Transform to put entities into MISP events☆28Updated 4 years ago
- Cyber Analytics Platform and Examination System (CAPES) Project Page☆14Updated 3 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆23Updated 4 years ago
- This repository is a curated list of pro bono incident response entities.☆21Updated 2 years ago
- ☆25Updated 3 years ago
- Custom Maltego transforms☆68Updated 10 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆42Updated 5 years ago
- RisingSun: Decoding SUNBURST C2 to identify infected hosts without network telemetry.☆10Updated 4 years ago
- Windows 10 Live Information viewer☆37Updated 3 years ago
- MacOS incident Response Toolkit. Mostly written while stuck on a NJTransit train.☆20Updated 5 years ago
- ☆22Updated 4 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Updated 9 years ago
- A simple many-rules to many-files YARA scanner for incident response or malware zoos.☆26Updated 7 years ago
- Synopsis is a tool to aid analysts reviewing browser history files by providing a high-level “synopsis” of key information.☆21Updated 7 years ago
- Log aggregation, analysis, alerting and correlation for Windows, Syslog and text based logs.☆23Updated 9 years ago
- 🦉🔬A small PowerShell tool for finding information quickly on malicious IPs or FQDNs. Powershell threat hunting.☆11Updated 5 years ago
- Collection of best practices to add OSINT into MISP and/or MISP communities☆66Updated 2 years ago
- ☆18Updated 7 years ago
- An extendable tool to extract and aggregate IoCs from threat feeds☆34Updated last year