mamun-sec / dfirt
Collect information of Windows PC when doing incident response
☆252Updated last year
Alternatives and similar repositories for dfirt:
Users that are interested in dfirt are comparing it to the libraries listed below
- MAL-CL (Malicious Command-Line)☆312Updated 2 years ago
- Collection of tools that reflect the network dimension into Bloodhound's data☆447Updated 2 years ago
- #ThreatHunting #DFIR #Malware #Detection Mind Maps☆297Updated 3 years ago
- ☆704Updated 2 months ago
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆850Updated 3 years ago
- Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.☆462Updated 9 months ago
- A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365☆782Updated 2 years ago
- Ransomware simulation script written in PowerShell. Useful for testing your defenses and backups against real ransomware-like activity in…☆222Updated 6 months ago
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆280Updated 8 months ago
- Ransomware simulator written in Golang☆433Updated 2 years ago
- Course repository for PowerShell for Pentesters Course☆431Updated 3 years ago
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆521Updated 2 years ago
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆612Updated 10 months ago
- Pwnspoof repository☆261Updated last year
- WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)☆781Updated 2 years ago
- An introduction to Active Directory security☆644Updated 2 years ago
- A PowerShell armoury for security guys and girls☆473Updated last year
- CVE-2021-1675 Detection Info☆216Updated last year
- Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack☆182Updated 3 years ago
- Deploy customizable Active Directory labs in Azure - automatically.☆418Updated 4 months ago
- A list of my personal projects☆176Updated 2 years ago
- Quietly enumerate an Active Directory Domain via LDAP parsing users, admins, groups, etc.☆489Updated 2 years ago
- A suite of Tools to aid Incidence Response and Live Forensics for - Windows (Powershell) | Linux (Bash) | MacOS (Shell)☆569Updated 6 months ago
- Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.☆201Updated 2 years ago
- Blue Team detection lab created with Terraform and Ansible in Azure.☆153Updated 5 months ago
- An Office365 User Attack Tool☆633Updated last year
- Custom PowerShell module to setup an Active Directory lab environment to practice penetration testing.☆176Updated 2 weeks ago
- Repository resource for threat hunter☆158Updated 6 years ago
- Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.☆481Updated 5 months ago
- Bloodhound Reporting for Blue and Purple Teams☆1,176Updated 2 months ago