herosi / triage-collector
☆21Updated 4 months ago
Alternatives and similar repositories for triage-collector:
Users that are interested in triage-collector are comparing it to the libraries listed below
- ☆34Updated 2 years ago
- Rapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence…☆56Updated 2 months ago
- ☆33Updated 2 years ago
- ETW forensic tool for Volatility3 plugin☆11Updated 3 months ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆58Updated 2 years ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated last year
- Modular malware analysis artifact collection and correlation framework☆53Updated 9 months ago
- ESXi Cyber Security Incident Response Script☆23Updated 5 months ago
- Imphash-like calculation on Golang binaries☆49Updated 2 years ago
- Winterfell hunt is a python script to perform auto threat hunting for malicious activities in windows OS based on collected data by winte…☆15Updated 4 years ago
- A collection of my yara rules☆35Updated last year
- A set of tools for collecting forensic information☆26Updated 4 years ago
- Linux #rootkit and #malware revealer☆23Updated 6 months ago
- Scripts and tools accompanying HP Threat Research blog posts and reports.☆50Updated 10 months ago
- Sample evtx files to use for testing hayabusa detection rules☆48Updated 3 months ago
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Updated 2 years ago
- Surface Analysis System on Cloud☆19Updated last year
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆32Updated 2 months ago
- Simple PowerShell script to enable process scanning with Yara.☆91Updated 2 years ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆76Updated last year
- Jupyter Notebooks for Cyber Threat Intelligence☆35Updated last year
- Just Another broken Registry Parser (JARP)☆16Updated 8 months ago
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Updated 2 years ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆51Updated last year
- Yara Rules for Modern Malware☆73Updated 11 months ago
- A powershell parser for https://github.com/ufrisk/MemProcFS☆44Updated 3 years ago
- Lazarus analysis tools and research report☆55Updated last year
- ShellSweeping the evil.☆52Updated 8 months ago
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆76Updated 3 years ago
- JPCERT/CC public YARA rules repository☆106Updated 2 months ago