mamun-sec / dfirtLinks
Collect information of Windows PC when doing incident response
☆252Updated 2 years ago
Alternatives and similar repositories for dfirt
Users that are interested in dfirt are comparing it to the libraries listed below
Sorting:
- Pwnspoof repository☆262Updated last year
- MAL-CL (Malicious Command-Line)☆314Updated 2 years ago
- Course repository for PowerShell for Pentesters Course☆432Updated 3 years ago
- A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365☆788Updated 2 years ago
- #ThreatHunting #DFIR #Malware #Detection Mind Maps☆298Updated 3 years ago
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆527Updated 2 years ago
- Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.☆468Updated last year
- Some Threat Hunting queries useful for blue teamers☆127Updated 3 years ago
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆326Updated 2 months ago
- A list of my personal projects☆177Updated 2 years ago
- Blue Team detection lab created with Terraform and Ansible in Azure.☆161Updated 7 months ago
- Repository resource for threat hunter☆158Updated 6 years ago
- Collection of tools that reflect the network dimension into Bloodhound's data☆447Updated 2 years ago
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆853Updated 3 years ago
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆620Updated last year
- Ransomware simulation script written in PowerShell. Useful for testing your defenses and backups against real ransomware-like activity in…☆228Updated 9 months ago
- ☆226Updated 2 years ago
- Incident Response collection and processing scripts with automated reporting scripts☆306Updated last year
- Russia / Ukraine 2022 conflict related IOCs from CERT Orange Cyberdefense Threat Intelligence Datalake☆175Updated 2 years ago
- Threat Hunting tool about Sysmon and graphs☆334Updated 2 years ago
- Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.☆204Updated 2 years ago
- A collection of intelligence about Log4Shell and its exploitation activity.☆183Updated 3 years ago
- Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study by Xena Olsen.☆656Updated 2 years ago
- Resources for DFIR Professionals Responding to the REvil Ransomware Kaseya Supply Chain Attack☆183Updated 4 years ago
- Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.☆482Updated 7 months ago
- Ransomware simulator written in Golang☆440Updated 3 years ago
- Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an…☆403Updated 4 months ago
- A python script developed to process Windows memory images based on triage type.☆263Updated last year
- This repo is where I store my Threat Hunting ideas/content☆88Updated 2 years ago
- ☆775Updated last week