mamun-sec / dfirtLinks
Collect information of Windows PC when doing incident response
☆253Updated 2 years ago
Alternatives and similar repositories for dfirt
Users that are interested in dfirt are comparing it to the libraries listed below
Sorting:
- MAL-CL (Malicious Command-Line)☆322Updated 3 years ago
- #ThreatHunting #DFIR #Malware #Detection Mind Maps☆306Updated 4 years ago
- Pwnspoof repository☆264Updated 2 years ago
- Course repository for PowerShell for Pentesters Course☆436Updated 3 years ago
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆342Updated last month
- A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365☆789Updated 3 years ago
- Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.☆481Updated last year
- A collection of intelligence about Log4Shell and its exploitation activity.☆184Updated 3 years ago
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆547Updated 3 years ago
- Russia / Ukraine 2022 conflict related IOCs from CERT Orange Cyberdefense Threat Intelligence Datalake☆174Updated 3 years ago
- Blue Team detection lab created with Terraform and Ansible in Azure.☆175Updated last year
- Incident Response collection and processing scripts with automated reporting scripts☆319Updated last year
- Repository resource for threat hunter☆158Updated 7 years ago
- Ransomware simulation script written in PowerShell. Useful for testing your defenses and backups against real ransomware-like activity in…☆238Updated last year
- Some Threat Hunting queries useful for blue teamers☆131Updated 3 years ago
- A list of my personal projects☆177Updated 3 years ago
- Threat Hunting tool about Sysmon and graphs☆335Updated 2 years ago
- Collection of tools that reflect the network dimension into Bloodhound's data☆446Updated 3 years ago
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆640Updated last year
- Ransomware simulator written in Golang☆470Updated 3 years ago
- A PoC ransomware sample to test out your ransomware response strategy.☆212Updated 2 months ago
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆860Updated 4 years ago
- PowerShell module for Office 365 and Azure log collection☆280Updated 3 months ago
- Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.☆207Updated 3 years ago
- ☆227Updated 3 years ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆250Updated 2 months ago
- A python script developed to process Windows memory images based on triage type.☆263Updated 2 years ago
- ☆194Updated last year
- PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.☆322Updated 8 months ago
- WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)☆780Updated 2 years ago