joachimmetz / artifactsLinks
ForensicArtifacts.com Artifact Repository
☆12Updated this week
Alternatives and similar repositories for artifacts
Users that are interested in artifacts are comparing it to the libraries listed below
Sorting:
- 2021 SANS DFIR Summit: Greppin' Logs☆20Updated 4 years ago
- This repository is a collection of EnScript code samples for use in the OpenText Endpoint Forensic and OpenText Endpoint Investigator app…☆54Updated 3 months ago
- Get all my software☆173Updated 4 months ago
- A framework for orchestrating forensic collection, processing and data export☆328Updated this week
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆210Updated last month
- ATT&CK Remote Threat Hunting Incident Response☆204Updated 10 months ago
- Library of functions to apply Data Science in several forensics artifacts☆40Updated last year
- Carbon Black Feeds☆73Updated 2 years ago
- "Evolving AppCompat/AmCache data analysis beyond grep"☆205Updated 4 years ago
- A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhanc…☆57Updated 3 months ago
- Scripts to facilitate filtering with Plaso☆127Updated 5 years ago
- Library of python scripts to apply Data Science in several forensics artifacts☆31Updated 5 years ago
- This is a set of tools for doing forensics analysis on Microsoft ESE databases.☆126Updated 3 years ago
- Splunk Content Control Tool☆119Updated last week
- ☆42Updated 4 years ago
- Software downloads☆109Updated 5 months ago
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆21Updated 4 years ago
- A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.☆235Updated 6 months ago
- Collection of SQL query templates for digital forensics use by platform and application.☆109Updated 4 years ago
- Pulls IOCs from MISP and adds the to reference sets in QRadar☆34Updated 2 years ago
- ☆54Updated 3 months ago
- The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted driv…☆340Updated 3 years ago
- Different DFIR and CTI utilities☆37Updated 5 years ago
- Real-time Response scripts and schema☆119Updated last year
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆77Updated last year
- Security Monitoring Resolution Categories☆138Updated 3 years ago
- ☆13Updated 3 years ago
- Carbon Black API - Python language bindings☆145Updated last year
- http://moaistory.blogspot.com/2016/08/ie10analyzer.html☆17Updated last year
- Splunk code (SPL) for serious threat hunters and detection engineers.☆287Updated last year