stuartjash / aftermathLinks
Aftermath is a free macOS incident response framework
☆34Updated last month
Alternatives and similar repositories for aftermath
Users that are interested in aftermath are comparing it to the libraries listed below
Sorting:
- Unleash the power of the Falcon Platform at the CLI☆131Updated 3 weeks ago
- Post-Infection Collection Toolkit☆95Updated 2 years ago
- Swift Command line tool used for proactive detection of malicious activity on macOS systems.☆68Updated 5 years ago
- Suite of tools to facilitate attacks against the Jamf macOS management platform.☆185Updated 4 years ago
- Aftermath is a free macOS IR framework☆545Updated last month
- https://wojciechregula.blog/post/macos-red-teaming-get-ad-credentials-from-nomad/☆42Updated 3 years ago
- Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations☆97Updated 2 months ago
- A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight,…☆25Updated last week
- MDM Migrator is now replaced by JUMP-IN☆24Updated 5 months ago
- A cross platform parser for Apple UnifiedLogs!☆283Updated 2 weeks ago
- Parser fo macOS/iOS FSEvents Logs☆38Updated last year
- Pokes users about outstanding security risks found by Crowdstrike Spotlight or vmware Workspace ONE so they secure their own endpoint.☆29Updated last week
- ☆26Updated 2 weeks ago
- A PowerShell-based script to analyze network logs from CSV files and detect potential beaconing behavior. Supports VirusTotal integration…☆17Updated 5 months ago
- This contains all the CrowdStrike API work I've done☆21Updated 5 years ago
- CrowdStrike Archive Scan Tool☆85Updated 3 years ago
- Automatic security lookups from your clipboard☆24Updated last year
- Queries from the blog posts.☆15Updated last year
- Collection of scripts/resources/ideas for attack surface reduction and additional logging to enable better threat hunting on Windows endp…☆38Updated last year
- ☆67Updated 2 years ago
- Parses USB connection artifacts from offline Registry hives☆101Updated 4 months ago
- LotL RMM☆249Updated last month
- ☆68Updated last week
- Advanced Hunting Queries☆19Updated last week
- A tool to run and validate telemetry for Atomic Red Team tests☆15Updated last year
- ESXi Cyber Security Incident Response Script☆25Updated last year
- Sigma detection rules for hunting with the threathunting-keywords project☆56Updated 7 months ago
- A triage data collection script for macOS☆28Updated 4 years ago
- ☆103Updated 3 months ago
- A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.☆159Updated 6 months ago