ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit logs using statistics and the MITRE ATT&CK Cloud Framework
☆183Mar 2, 2026Updated 4 months ago
Alternatives and similar repositories for ALFA
Users that are interested in ALFA are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆232Oct 26, 2025Updated 9 months ago
- A tool for AWS incident response, that allows for enumeration, acquisition and analysis of data from AWS environments for the purpose of …☆204Jan 6, 2026Updated 6 months ago
- A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.☆832Jun 29, 2026Updated 3 weeks ago
- Parses USB connection artifacts from offline Registry hives☆109Feb 8, 2026Updated 5 months ago
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Feb 6, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆84Jan 6, 2026Updated 6 months ago
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆35Jul 12, 2023Updated 3 years ago
- ☆72Oct 21, 2024Updated last year
- Notes on responding to security breaches relating to Azure AD☆123Mar 14, 2022Updated 4 years ago
- The Business Email Compromise Guide sets out to describe 10 steps for performing a Business Email Compromise (BEC) investigation in an Of…☆282Feb 2, 2021Updated 5 years ago
- Repository of attack and defensive information for Business Email Compromise investigations☆278Jun 17, 2026Updated last month
- A dataset containing Office 365 Unified Audit Logs for security research and detection☆62Jun 7, 2022Updated 4 years ago
- PowerShell module for Office 365 and Azure log collection☆282Sep 22, 2025Updated 10 months ago
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of par…☆254Nov 18, 2024Updated last year
- Extract BITS jobs from QMGR queue and store them as CSV records☆74Feb 13, 2025Updated last year
- DeRF (Detection Replay Framework) is an "Attacks As A Service" framework, allowing the emulation of offensive techniques and generation o…☆101Jan 12, 2024Updated 2 years ago
- USN Journal full path builder☆69Apr 16, 2026Updated 3 months ago
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆14Jun 27, 2023Updated 3 years ago
- Powershell module for VMWare vSphere forensics☆185Nov 8, 2024Updated last year
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆182Updated this week
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆666Jul 6, 2026Updated 2 weeks ago
- Aftermath is a free macOS IR framework☆594Sep 25, 2025Updated 10 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆80Jan 9, 2024Updated 2 years ago
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆21Oct 25, 2023Updated 2 years ago
- ESXi Cyber Security Incident Response Script☆28Sep 4, 2024Updated last year
- DFIQ is a collection of investigative questions and the approaches for answering them☆310Mar 10, 2026Updated 4 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆728May 2, 2026Updated 2 months ago
- ☆152Jun 5, 2024Updated 2 years ago
- ☆76Mar 19, 2025Updated last year
- ☆23Mar 12, 2025Updated last year
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆43Sep 21, 2023Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆27Mar 2, 2022Updated 4 years ago
- CyLR - Live Response Collection Tool☆732Jun 1, 2022Updated 4 years ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆837May 30, 2026Updated last month
- This tool aims at parsing Microsoft Protection logs to provide relevant data to forensic analysts during incident responses.☆22Sep 30, 2022Updated 3 years ago
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,414Jul 1, 2026Updated 3 weeks ago
- Tool to extract Sessions, MessageID(s) and find the emails belonging to MessageID(s). This script utilizes the MailItemsAccessed features…☆43Oct 20, 2020Updated 5 years ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆89Feb 9, 2025Updated last year