megan201296 / gsuite-dfirView external linksLinks
☆42Dec 13, 2020Updated 5 years ago
Alternatives and similar repositories for gsuite-dfir
Users that are interested in gsuite-dfir are comparing it to the libraries listed below
Sorting:
- my MSTICpy practice and custom tools repository☆11Apr 23, 2025Updated 9 months ago
- 2021 SANS DFIR Summit: Greppin' Logs☆20Oct 30, 2025Updated 3 months ago
- This module installs and configures MISP (Malware Information Sharing Platform)☆14Dec 29, 2025Updated last month
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 9 years ago
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆219Oct 26, 2025Updated 3 months ago
- My Jupyter Notebooks☆36Mar 14, 2025Updated 11 months ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆43Jul 18, 2022Updated 3 years ago
- The gse-study repo was assembled to serve as a consolidated, and comprehensive, study solution for the SANS GSE exam.☆25Nov 11, 2018Updated 7 years ago
- AWS Live Response☆11Sep 19, 2017Updated 8 years ago
- EPSScall☆11Jun 10, 2022Updated 3 years ago
- Home to the ActorTrackr source code☆24Jun 21, 2017Updated 8 years ago
- This is to edit a training forensic image file (raw/dd) and zero out all the unnecessary files.☆11Jun 21, 2025Updated 7 months ago
- SmartResponse plugin development.☆15Sep 25, 2019Updated 6 years ago
- tlsplayback is a set of Proof of Concepts (PoC) showing real-world replay attacks against TLS 1.3 libraries and browsers by exploiting 0-…☆16Aug 11, 2018Updated 7 years ago
- Presentation Slides and Video links☆32Nov 8, 2021Updated 4 years ago
- A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhanc…☆59Jun 24, 2025Updated 7 months ago
- This repository contains all the config files and scripts used for our Open Source Endpoint monitoring project.☆35Jul 8, 2019Updated 6 years ago
- python3 scripts to help with aws triage needs☆15Feb 11, 2022Updated 4 years ago
- defendA Data Lake. A firehose pipeline to athena providing enrichment and normalization for security events☆17Apr 19, 2023Updated 2 years ago
- A repository to host emojis used in the Digital Forensics Discord Server☆18May 28, 2022Updated 3 years ago
- This repository contains the code and PCAPS used for the SANS webinar, "Hacking Proprietary Protocols" given on February 23, 2021.☆34Apr 9, 2022Updated 3 years ago
- The Business Email Compromise Guide sets out to describe 10 steps for performing a Business Email Compromise (BEC) investigation in an Of…☆277Feb 2, 2021Updated 5 years ago
- Windows Forensics Salt States☆21Updated this week
- Term concordances for each course in the SANS DFIR curriculum. Used for automated index generation.☆69Aug 7, 2020Updated 5 years ago
- ☆68Nov 25, 2025Updated 2 months ago
- Collection of scripts provided for public use☆39Feb 4, 2026Updated last week
- Collection of Slides From My Conference Talks☆20Nov 21, 2022Updated 3 years ago
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆817Feb 9, 2026Updated last week
- Elasticsearch / Kibana for Unifi USG and CloudKey (gen2)☆19Jun 5, 2020Updated 5 years ago
- A script to create and assign SOP tasks into the cases☆20Aug 16, 2020Updated 5 years ago
- Utilizing your Threat data from a MISP instance into CarbonBlack Response by exposing the data in the Threat Intelligence Feed.☆20May 25, 2022Updated 3 years ago
- MS Word (DOCx) Parsing Tool☆23Feb 2, 2026Updated 2 weeks ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆78Jan 9, 2024Updated 2 years ago
- ☆77Jun 25, 2019Updated 6 years ago
- Data exfiltration using DNS☆24Dec 28, 2019Updated 6 years ago
- Collection of useful, up to date, Carbon Black Response Queries☆84Oct 23, 2020Updated 5 years ago
- ☆50Aug 30, 2020Updated 5 years ago
- A dataset containing Office 365 Unified Audit Logs for security research and detection☆60Jun 7, 2022Updated 3 years ago
- The home of the BriMor Labs rdpieces Perl script that tries to rebuild parsed RDP Bitmap Cache images☆89Aug 29, 2023Updated 2 years ago