ktneely / forensics
shell script to create an image and perform initial examination on a drive
☆15Updated 4 years ago
Alternatives and similar repositories for forensics:
Users that are interested in forensics are comparing it to the libraries listed below
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆41Updated 4 years ago
- Python bindings for Yeti's API☆18Updated last year
- Metadata Inspection Database Alerting System☆42Updated 11 years ago
- CRITs Services Collection☆15Updated 7 years ago
- Build Automated Machine Images for MISP☆28Updated last year
- This repository is a curated list of pro bono incident response entities.☆20Updated last year
- Yara Scanner For IMAP Feeds and saved Streams☆28Updated 5 years ago
- Incident Response Scripts☆30Updated 4 years ago
- Maltego Transform to put entities into MISP events☆26Updated 3 years ago
- Auxiliary scripts for Incident Response with ELK☆11Updated 9 years ago
- Digital Forensics and Incident Response Wiki☆40Updated 10 years ago
- ☆10Updated 8 years ago
- Fast incident overview☆39Updated 7 years ago
- Threat Intel and Incident Reponse☆10Updated 6 years ago
- Home to the ActorTrackr source code☆24Updated 7 years ago
- ☆12Updated 5 years ago
- FireEye Alert json files to MISP Malware information sharing plattform (Alpha)☆32Updated 7 years ago
- Small scripts and POCs related to digital forensics☆17Updated 2 years ago
- A tool to convert MISP XML files (events and attributes) into graphs☆20Updated 7 years ago
- Based on the Volatility framework, this script will run various plugins as well as create a timeline, or use YARA/ClamAV/VirusTotal to fi…☆49Updated 7 years ago
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated last year
- Parse IE, FireFox, Chrome and Safari Cookies for Google Analytic values☆23Updated 8 years ago
- Discover potential timestamps within the Windows Registry☆18Updated 10 years ago
- Forensic Scanner☆40Updated 12 years ago
- An active domain name query tool to help keep track of domain name movements...☆15Updated 3 years ago
- CRITs IOC Visualization in Maltego☆28Updated 10 years ago
- Home to the ActorTrackr source code☆28Updated 7 years ago
- CDPO is a tool to validate, de-duplicate, combine, query, and encrypt track data recovered from a breach.☆15Updated 7 years ago