mamun-sec / dfirtLinks
Collect information of Windows PC when doing incident response
☆252Updated 2 years ago
Alternatives and similar repositories for dfirt
Users that are interested in dfirt are comparing it to the libraries listed below
Sorting:
- Pwnspoof repository☆265Updated 2 years ago
- #ThreatHunting #DFIR #Malware #Detection Mind Maps☆303Updated 4 years ago
- A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365☆789Updated 3 years ago
- MAL-CL (Malicious Command-Line)☆319Updated 2 years ago
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆338Updated 2 weeks ago
- Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.☆477Updated last year
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆538Updated 3 years ago
- Course repository for PowerShell for Pentesters Course☆433Updated 3 years ago
- Repository resource for threat hunter☆158Updated 7 years ago
- Blue Team detection lab created with Terraform and Ansible in Azure.☆168Updated last year
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆859Updated 3 years ago
- A list of my personal projects☆177Updated 3 years ago
- Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.☆487Updated last year
- Ransomware simulator written in Golang☆453Updated 3 years ago
- Collection of tools that reflect the network dimension into Bloodhound's data☆443Updated 3 years ago
- Some Threat Hunting queries useful for blue teamers☆131Updated 3 years ago
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆634Updated last year
- Incident Response collection and processing scripts with automated reporting scripts☆314Updated last year
- SMBeagle - Fileshare auditing tool.☆733Updated 2 weeks ago
- A suite of Tools to aid Incidence Response and Live Forensics for - Windows (Powershell) | Linux (Bash) | MacOS (Shell)☆600Updated last year
- Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study by Xena Olsen.☆668Updated 2 years ago
- PowerShell module for Office 365 and Azure log collection☆276Updated last month
- Threat Hunting tool about Sysmon and graphs☆333Updated 2 years ago
- Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.☆208Updated 3 years ago
- A collection of intelligence about Log4Shell and its exploitation activity.☆184Updated 3 years ago
- ☆226Updated 3 years ago
- ☆195Updated last year
- Purple Teaming Attack & Hunt Lab - Terraform☆161Updated 3 years ago
- A python script developed to process Windows memory images based on triage type.☆265Updated last year
- Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...☆1,087Updated last week