strozfriedberg / greppin-logsView external linksLinks
2021 SANS DFIR Summit: Greppin' Logs
☆20Oct 30, 2025Updated 3 months ago
Alternatives and similar repositories for greppin-logs
Users that are interested in greppin-logs are comparing it to the libraries listed below
Sorting:
- ☆42Dec 13, 2020Updated 5 years ago
- The Business Email Compromise Guide sets out to describe 10 steps for performing a Business Email Compromise (BEC) investigation in an Of…☆277Feb 2, 2021Updated 5 years ago
- Resource links (video, slides & code) for my conference talks | presentations | workshops☆21Nov 17, 2025Updated 2 months ago
- Repo to track SANS BlueTeam Summit Presentation☆23Oct 4, 2022Updated 3 years ago
- A dataset containing Office 365 Unified Audit Logs for security research and detection☆60Jun 7, 2022Updated 3 years ago
- ATT&CK Remote Threat Hunting Incident Response☆206Dec 8, 2024Updated last year
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆24Jul 9, 2021Updated 4 years ago
- A Backup for BMC Viewer☆33Nov 4, 2017Updated 8 years ago
- Script to automate Linux live evidence collection☆28Aug 4, 2022Updated 3 years ago
- Active Directory Purple Team Playbook☆115May 8, 2023Updated 2 years ago
- PowerShell module for Microsoft Graph REST API. To optimize, speed, and bulk use Microsoft Graph API in PowerShell. You can can enter you…☆30Nov 18, 2022Updated 3 years ago
- ☆73Oct 21, 2024Updated last year
- ☆13Nov 29, 2021Updated 4 years ago
- Some dfir stuff☆31Jan 12, 2022Updated 4 years ago
- Defence Against the Dark Arts☆34Sep 15, 2019Updated 6 years ago
- Windows Security Logging☆43Jul 17, 2022Updated 3 years ago
- A module for CME that spiders across a domain.☆35Jul 15, 2022Updated 3 years ago
- PowerSponse is a PowerShell module focused on targeted containment and remediation during incident response.☆40Mar 18, 2022Updated 3 years ago
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆39Dec 17, 2025Updated last month
- Collection of PowerShell functinos and scripts a Blue Teamer might use☆88Oct 4, 2023Updated 2 years ago
- Scripts and things.☆13Jan 23, 2026Updated 3 weeks ago
- This repository contains the code and PCAPS used for the SANS webinar, "Hacking Proprietary Protocols" given on February 23, 2021.☆34Apr 9, 2022Updated 3 years ago
- ☆33Oct 25, 2021Updated 4 years ago
- ☆14Feb 6, 2026Updated last week
- A python script developed to process Windows memory images based on triage type.☆264Nov 25, 2023Updated 2 years ago
- ReWrite of AChoir in Go for Cross Platform forensic artifact collection and processing☆41Feb 2, 2026Updated last week
- ☆34Apr 29, 2021Updated 4 years ago
- Deploy and maintain Symon through the Splunk Deployment Sever☆32Jul 30, 2020Updated 5 years ago
- The home of the BriMor Labs rdpieces Perl script that tries to rebuild parsed RDP Bitmap Cache images☆89Aug 29, 2023Updated 2 years ago
- KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.☆18Nov 7, 2024Updated last year
- Dump macOS 1.8+ password hashes to a hashcat-compatible format☆14May 29, 2022Updated 3 years ago
- Automate ISSG Tool Setups☆13Nov 21, 2024Updated last year
- 🔥🔥🔥 AI security automation platform. Build visual workflows, deploy autonomous agents, and automate threat detection and response. 80+…☆27Updated this week
- Fluxion is a easy to use wifi cracker, to test your own network☆11Feb 8, 2017Updated 9 years ago
- Most Popular Attack and Defend Competitive A/D mode for 5 years!☆12Feb 5, 2018Updated 8 years ago
- A small crappy script I wrote that converts the Sigma Windows Process Creation events to KQL via PySigma. Designed for CI/CD☆10Nov 7, 2023Updated 2 years ago
- Library of threat hunts to get any user started!☆48Sep 4, 2020Updated 5 years ago
- ☆39Jun 28, 2019Updated 6 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆43Jul 18, 2022Updated 3 years ago