rshipp / ir-triage-toolkitView external linksLinks
Create an incident response triage toolkit for use with Windows or Linux.
☆18Jun 14, 2020Updated 5 years ago
Alternatives and similar repositories for ir-triage-toolkit
Users that are interested in ir-triage-toolkit are comparing it to the libraries listed below
Sorting:
- Automating forensic data extraction, reduction, and overall triage of cold disk and memory images.☆21Mar 12, 2019Updated 6 years ago
- Light System Examination Toolkit (LISET) - logs & activity & configuration gathering utility that comes handy in fast Windows incident re…☆32Aug 29, 2016Updated 9 years ago
- Network Defender Toolkit☆18Jun 11, 2013Updated 12 years ago
- ETW-Almulahaza is a consumer python-based tool that help you monitor ETW events of the operating system☆13Jun 24, 2022Updated 3 years ago
- A framework that correlates Bro events☆18Oct 25, 2013Updated 12 years ago
- F-Secure Lightweight Acqusition for Incident Response (FLAIR)☆16Jul 5, 2021Updated 4 years ago
- Python script to pull various IOCs from PDFs☆15Dec 22, 2014Updated 11 years ago
- MCP Server that integrates with Security Copilot, Sentinel and other tools (in the future). It enhance the process of developing , testin…☆20Oct 8, 2025Updated 4 months ago
- Microsoft GPO Readiness Lateral Movement Detection Tool☆16Dec 8, 2022Updated 3 years ago
- Automated install scripts for Cuckoo sandbox☆38Dec 5, 2017Updated 8 years ago
- dnssinkholelist is a python package focused on combining open source lists of malicious domains, dynamic dns domains, and advertisement d…☆18Apr 13, 2016Updated 9 years ago
- openioc_scan Volatility Framework plugin☆44Feb 25, 2016Updated 9 years ago
- ☆28Oct 15, 2025Updated 4 months ago
- Polyglot detector☆23Jun 5, 2025Updated 8 months ago
- Various Bro scripts☆37May 20, 2014Updated 11 years ago
- Beholder is a shell script which installs and configures essentials to peer into your network activity.☆19Jun 19, 2017Updated 8 years ago
- Collection of information security policies.☆29Apr 20, 2017Updated 8 years ago
- Public Maltego Transforms☆24May 24, 2017Updated 8 years ago
- This repository is a curated list of pro bono incident response entities.☆21Jun 21, 2023Updated 2 years ago
- Contributed Bro Scripts☆30May 28, 2014Updated 11 years ago
- Forensics triage tool relying on Volatility and Foremost☆25Dec 3, 2023Updated 2 years ago
- Linux Baseline and Forensic Triage Tool - BETA☆57Sep 8, 2022Updated 3 years ago
- Code for the DIMVA 2018 paper: "MemScrimper: Time- and Space-Efficient Storage of Malware Sandbox Memory Dumps"☆26Jul 22, 2019Updated 6 years ago
- Network Forensics Bro scripts & pcap samples☆63Mar 11, 2014Updated 11 years ago
- ☆84Aug 7, 2013Updated 12 years ago
- Pythonic interface to the Internet Storm Center / DShield API.☆28May 23, 2023Updated 2 years ago
- CuckooMX is a project to automate analysis of files transmitted over SMTP (using the Cuckoo sandbox)☆40Aug 2, 2012Updated 13 years ago
- Network sinkhole for isolated malware analysis☆40Mar 5, 2018Updated 7 years ago
- Integrating Sysinternals Autoruns’ logs into Security Onion☆31Feb 20, 2024Updated last year
- Apache Logfile Security Analyzer☆214Feb 22, 2019Updated 6 years ago
- A powerful hardware ID spoofing tool designed to modify system identifiers for privacy and security purposes. Change MAC addresses, HWID,…☆17Nov 26, 2025Updated 2 months ago
- File integrity monitor with malware detection using machine learning☆14May 23, 2024Updated last year
- Tools for the Computer Incident Response Team☆150Apr 17, 2017Updated 8 years ago
- An automated collection and analysis of malware from my honeypots.☆25Feb 8, 2018Updated 8 years ago
- Manage VT Alerts☆62Oct 4, 2016Updated 9 years ago
- Bro scripts to be shared with the community☆110Mar 6, 2013Updated 12 years ago
- SANS Hunting on the Cheap☆36Apr 12, 2016Updated 9 years ago
- Dump of organized knowledge on DFIR☆138Oct 4, 2021Updated 4 years ago
- Simple host-based permit-by-exception iptables generation script☆16Sep 5, 2020Updated 5 years ago