google / docker-explorer
A tool to help forensicate offline docker acquisitions
☆543Updated 7 months ago
Alternatives and similar repositories for docker-explorer
Users that are interested in docker-explorer are comparing it to the libraries listed below
Sorting:
- (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR)…☆634Updated last year
- Python library to carry out DFIR analysis on the Cloud☆477Updated last month
- A repository for using osquery for incident detection and response☆847Updated 2 years ago
- A framework for orchestrating forensic collection, processing and data export☆313Updated this week
- Automation and Scaling of Digital Forensics Tools☆765Updated 2 months ago
- AutoMacTC: Automated Mac Forensic Triage Collector☆540Updated 3 years ago
- Real-time, container-based file scanning at enterprise scale☆918Updated last month
- Remote Memory Acquisition Tool☆245Updated 4 years ago
- A Linux Auditd rule set mapped to MITRE's Attack Framework☆789Updated 4 years ago
- Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux☆499Updated 2 years ago
- Python installable command line utiltity for mitigation of host and key compromises.☆346Updated 3 years ago
- osquery extensions by Trail of Bits☆264Updated 2 years ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆791Updated 2 years ago
- A production-friendly malware scanner for your AWS cloud☆199Updated 3 years ago
- AVML - Acquire Volatile Memory for Linux☆942Updated this week
- an osquery fleet manager☆617Updated 2 years ago
- Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of par…☆253Updated 5 months ago
- Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.☆1,303Updated 2 years ago
- Chain Reactor is an open source framework for composing executables that simulate adversary behaviors and techniques on Linux endpoints.☆311Updated last month
- Fast and efficient osquery management☆443Updated last month
- Production-ready detection & response queries for osquery☆567Updated last week
- YARA malware query accelerator (web frontend)☆426Updated last month
- Digital Forensics artifact repository☆1,112Updated 4 months ago
- 1-Click push forensics evidence to the cloud☆142Updated 10 months ago
- Cuckoo Sandbox Dockerfile☆327Updated 5 years ago
- Awesome list of resources related to container security☆235Updated 5 months ago
- Yet Another Yara Automaton - Automatically curate open source yara rules and run scans☆280Updated last year
- Yara integrated software to handle archive file data.☆308Updated 3 years ago
- Modular file scanning/analysis framework☆618Updated 5 years ago
- DFIRTrack - The Incident Response Tracking Application☆498Updated 8 months ago