hslatman / awesome-incident-response
A curated list of tools for incident response
☆19Updated 5 years ago
Alternatives and similar repositories for awesome-incident-response:
Users that are interested in awesome-incident-response are comparing it to the libraries listed below
- A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.☆24Updated 8 years ago
- A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for t…☆14Updated 8 years ago
- A curated list of awesome social engineering resources.☆15Updated 7 years ago
- An informational repo about hunting for adversaries in your IT environment.☆14Updated 7 years ago
- ☆29Updated 6 years ago
- Use DNS to hunt for threats including DGAs☆14Updated 9 years ago
- Indices for courses in SANS' Network Security Operations curriculum☆15Updated 8 years ago
- Knowledge base of analytics designed to cover threats based on MITRE's ATT&CK.☆22Updated 6 years ago
- OSSEC Decoder & Rulesets for Sysmon Events☆15Updated 9 years ago
- This package allows for creating alerts in The Hive from emails retrieved from a Microsoft Exchange mailbox.☆12Updated 7 years ago
- A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development☆12Updated 7 years ago
- Build your own threat hunting maturity model☆11Updated 7 years ago
- A set of templates for documenting threat intelligence☆74Updated 11 years ago
- Web based analysis platform for use with the AWS_IR command line tool.☆17Updated 8 years ago
- mindmap created for tools can be used during analysis/investigation☆27Updated 8 years ago
- Fast incident overview☆39Updated 7 years ago
- Powershell collection designed to assist in Threat Hunting Windows systems.☆27Updated 6 years ago
- incident response scripts☆19Updated 5 years ago
- A script to create and assign SOP tasks into the cases☆18Updated 4 years ago
- Cyber Analytics Platform and Examination System (CAPES) Project Page☆14Updated 2 years ago
- irCRpull is a PowerShell script utilized to pull several system artifacts, utilizing the free tool CrowdResponse, from a live Win7+ syste…☆13Updated 9 years ago
- Security Operations Center Multiple Purpose Tool, takes IP address input, conducts OSINT, conducts splunk, bro, fireeye, imperva, and fir…☆21Updated 7 years ago
- FireEye Alert json files to MISP Malware information sharing plattform (Alpha)☆32Updated 7 years ago
- ☆14Updated 4 years ago
- Home to the ActorTrackr source code☆24Updated 7 years ago
- Transforms for the AlienVault OTX service☆39Updated 8 years ago
- A curated list of awesome threat detection and hunting resources☆10Updated 6 years ago
- FireEye iSIGHT Alert Feeder for TheHive, an Open Source and Free Security Incident Response Platform☆16Updated 6 years ago
- Integrating Sysinternals Autoruns’ logs into Security Onion☆31Updated 11 months ago