Tools for the Computer Incident Response Team
☆152Apr 17, 2017Updated 9 years ago
Alternatives and similar repositories for CIRTKit
Users that are interested in CIRTKit are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Carbonblack Live Response from the comfort of your own terminal☆20Jan 20, 2016Updated 10 years ago
- Multithreaded threat Intelligence gathering built with Python3☆178Jan 23, 2018Updated 8 years ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆41Jul 29, 2020Updated 6 years ago
- LNK to JSON☆14Mar 7, 2019Updated 7 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Cyber Intel Management☆50Jan 25, 2018Updated 8 years ago
- Digital forensic acquisition tool for Windows based incident response.☆348May 7, 2024Updated 2 years ago
- PyMal is a python based interactive Malware Analysis Framework. It is built on the top of three pure python programes Pefile, Pydbg and V…☆43Jul 10, 2016Updated 10 years ago
- Incident Response Triage - Windows Evidence Collection for Forensic Analysis☆139Apr 21, 2016Updated 10 years ago
- Auxiliary scripts for Incident Response with ELK☆11Oct 7, 2015Updated 10 years ago
- Python tool and library to help analyze files during malware triage and analysis.☆79Jul 2, 2020Updated 6 years ago
- DFIRTrack - The Incident Response Tracking Application☆538Jan 13, 2026Updated 7 months ago
- DPS' Lightweight Investigation Notebook☆435Dec 31, 2023Updated 2 years ago
- Test Blue Team detections without running any attack.☆271May 2, 2024Updated 2 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across al…☆656Aug 19, 2019Updated 7 years ago
- A Python library for being a CND Batman....☆36Oct 29, 2015Updated 10 years ago
- Some IR notes☆72Jul 23, 2016Updated 10 years ago
- Light System Examination Toolkit (LISET) - logs & activity & configuration gathering utility that comes handy in fast Windows incident re…☆32Aug 29, 2016Updated 10 years ago
- CIF v3 -- the fastest way to consume threat intelligence☆189Apr 20, 2023Updated 3 years ago
- ThreatTracker is a Python script designed to monitor and generate alerts on given sets of indicators of compromise (IOCs) indexed by a se…☆71Mar 9, 2015Updated 11 years ago
- Query and report user logons relations from MS Windows Security Events☆241Aug 9, 2018Updated 8 years ago
- Python script to decode common encoded PowerShell scripts☆216Jun 13, 2018Updated 8 years ago
- A modular Python application to pull intelligence about malicious files☆123Dec 4, 2020Updated 5 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- PowerShell No Agent Hunting☆111Apr 23, 2018Updated 8 years ago
- Invoke-LiveResponse☆150Feb 22, 2022Updated 4 years ago
- ReviveIT (revit) is a proof of concept file recovery tool (carver)☆13Dec 3, 2020Updated 5 years ago
- Allows you to quickly query a Windows machine for RAM artifacts☆219Jul 17, 2020Updated 6 years ago
- Fast Incident Response☆2,032Aug 7, 2026Updated 3 weeks ago
- A modular Python application to collect intelligence for malicious hosts.☆274Apr 13, 2021Updated 5 years ago
- Small and highly portable detection tests based on MITRE's ATT&CK.☆11Feb 17, 2025Updated last year
- Extract information from MISP via the API☆16Jul 18, 2016Updated 10 years ago
- Tools from WFA 4/e, timeline tools, etc.☆146Feb 29, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Automating forensic data extraction, reduction, and overall triage of cold disk and memory images.☆21Mar 12, 2019Updated 7 years ago
- "Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security …☆1,039May 27, 2020Updated 6 years ago
- Modular command-line threat hunting tool & framework.☆17Jul 20, 2020Updated 6 years ago
- MacOS incident Response Toolkit. Mostly written while stuck on a NJTransit train.☆20Feb 20, 2020Updated 6 years ago
- Signature engine for all your logs☆172Nov 13, 2023Updated 2 years ago
- A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.☆488Feb 21, 2021Updated 5 years ago
- Indicator Extractor☆141Jul 14, 2018Updated 8 years ago