log2timeline / dftimewolfLinks
A framework for orchestrating forensic collection, processing and data export
β341Updated last week
Alternatives and similar repositories for dftimewolf
Users that are interested in dftimewolf are comparing it to the libraries listed below
Sorting:
- User guide of MISPβ282Updated last year
- π§ The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux systemβ304Updated 9 months ago
- A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.β255Updated 10 months ago
- Modules for expansion services, enrichment, import and export in MISP and other tools.β361Updated this week
- DFIRTrack - The Incident Response Tracking Applicationβ532Updated 3 weeks ago
- β176Updated last year
- The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted drivβ¦β344Updated 3 years ago
- Collect, Process, and Hunt with host based data from MacOS, Windows, and Linuxβ504Updated 3 years ago
- Python API Client for TheHiveβ234Updated 2 months ago
- Documentation of Cortexβ174Updated 2 years ago
- Cortex Analyzers Repositoryβ476Updated this week
- MISP trainings, threat intel and information sharing training materials with source codeβ422Updated last month
- Sigma rules from Joe Securityβ230Updated last year
- β227Updated 2 years ago
- A threat hunting / data analysis environment based on Python, Pandas, PySpark and Jupyter Notebook.β252Updated 4 years ago
- Dump of organized knowledge on DFIRβ138Updated 4 years ago
- SIEGMA - Transform Sigma rules into SIEM consumablesβ159Updated 11 months ago
- This is a repository for freq.py and freq_server.pyβ214Updated last week
- Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.β295Updated last week
- Splunk code (SPL) for serious threat hunters and detection engineers.β289Updated 2 years ago
- A curated list of awesome things related to TheHive & Cortexβ184Updated 4 years ago
- ATT&CK Remote Threat Hunting Incident Responseβ206Updated last year
- DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted β¦β339Updated last year
- Collecting & Hunting for IOCs with gusto and styleβ241Updated 4 years ago
- MISP Docker (XME edition)β282Updated 2 years ago
- Salt States for Configuring the SIFT Workstationβ107Updated 3 weeks ago
- Mark Baggett's (@MarkBaggett - GSE #15, SANS SEC573 Author) tool for detecting randomness using NLP techniques rather than pure entropy cβ¦β129Updated 3 years ago
- Documentation of TheHiveβ400Updated 2 years ago
- Security Monitoring Resolution Categoriesβ138Updated 4 years ago
- OASIS TC Open Repository: TAXII 2 Client Library Written in Pythonβ120Updated last year