silascutler / awesome-docker-malware-analysisLinks
Repository of tools and resources for analyzing Docker containers
☆66Updated last year
Alternatives and similar repositories for awesome-docker-malware-analysis
Users that are interested in awesome-docker-malware-analysis are comparing it to the libraries listed below
Sorting:
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆52Updated 7 months ago
- Repository that contains a set of purposefully erroneous Yara rules.☆52Updated last year
- Rules Shared by the Community from 100 Days of YARA 2023☆77Updated 2 years ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆64Updated 2 years ago
- Further investigation in to APT campaigns disclosed by private security firms and security agencies☆86Updated 3 years ago
- C2 Active Scanner☆59Updated last year
- The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders und…☆124Updated last year
- Detection Engineering with YARA☆87Updated last year
- Rules shared by the community from 100 Days of YARA 2025☆33Updated 5 months ago
- BlackBerry Threat Research & Intelligence☆98Updated last year
- Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or event…☆78Updated 4 years ago
- IOC Stream and Command and Control Database Containing Command and Control (C2) Servers Detected Daily by ThreatMon.☆66Updated last year
- A toolkit for the post-mortem examination of Docker containers from forensic HDD copies☆103Updated last year
- Data from Dark Web Marketplace scraping - Be careful☆40Updated 8 months ago
- CarbonBlack EDR detection rules and response actions☆71Updated 10 months ago
- God Mode Detection Rules☆134Updated 11 months ago
- BSidesRoc 2022 Linux Malware/Forensics Course☆76Updated 3 years ago
- Actively hunt for attacker infrastructure by filtering Shodan results with URLScan data.☆61Updated 11 months ago
- ATT&CK Powered Suit is a browser extension that puts the complete MITRE ATT&CK® knowledge base at your fingertips with text search, conte…☆78Updated last month
- An experimental Velociraptor implementation using cloud infrastructure☆25Updated 2 weeks ago
- Rapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence…☆67Updated last month
- The Threat Actor Profile Guide for CTI Analysts☆108Updated 2 years ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆33Updated 2 weeks ago
- A CALDERA plugin☆26Updated 11 months ago
- Convert Sigma rules to SIEM queries, directly in your browser.☆91Updated last week
- ☆51Updated 3 weeks ago
- Raw data from Threat Intelligence Reports with automatic reports collection and keyword search across thousands of reports☆122Updated last week
- A YARA & Malware Analysis Toolkit written in Rust.☆36Updated last week
- A MITRE ATT&CK Lookup Tool☆45Updated last year
- Graphical map of known Advanced Persistent Threats☆54Updated 3 months ago