log2timeline / dftimewolfLinks
A framework for orchestrating forensic collection, processing and data export
β341Updated last week
Alternatives and similar repositories for dftimewolf
Users that are interested in dftimewolf are comparing it to the libraries listed below
Sorting:
- User guide of MISPβ282Updated last year
- π§ The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux systemβ304Updated 9 months ago
- DFIRTrack - The Incident Response Tracking Applicationβ532Updated 3 weeks ago
- The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted drivβ¦β344Updated 3 years ago
- Modules for expansion services, enrichment, import and export in MISP and other tools.β361Updated last week
- A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.β255Updated 10 months ago
- β176Updated last year
- Collect, Process, and Hunt with host based data from MacOS, Windows, and Linuxβ504Updated 3 years ago
- A curated list of awesome things related to TheHive & Cortexβ184Updated 4 years ago
- Documentation of Cortexβ174Updated 2 years ago
- MISP trainings, threat intel and information sharing training materials with source codeβ422Updated last month
- Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.β295Updated last week
- Python API Client for TheHiveβ234Updated this week
- A threat hunting / data analysis environment based on Python, Pandas, PySpark and Jupyter Notebook.β252Updated 4 years ago
- Cortex Analyzers Repositoryβ476Updated this week
- β227Updated 2 years ago
- SIEGMA - Transform Sigma rules into SIEM consumablesβ159Updated 11 months ago
- Dump of organized knowledge on DFIRβ138Updated 4 years ago
- This is a repository for freq.py and freq_server.pyβ214Updated last week
- Splunk code (SPL) for serious threat hunters and detection engineers.β289Updated 2 years ago
- A Splunk app to use MISP in backgroundβ113Updated last month
- A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.β388Updated 3 years ago
- DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted β¦β339Updated last year
- CASCADE Serverβ274Updated 3 years ago
- Salt States for Configuring the SIFT Workstationβ107Updated this week
- OASIS TC Open Repository: TAXII 2 Client Library Written in Pythonβ120Updated last year
- Documentation of TheHiveβ400Updated 2 years ago
- Security Monitoring Resolution Categoriesβ138Updated 4 years ago
- Scripts to facilitate filtering with Plasoβ128Updated 5 years ago
- CyLR - Live Response Collection Toolβ708Updated 3 years ago