w8mej / IRKnowledge
A curated list of tools for incident response
☆28Updated 10 months ago
Alternatives and similar repositories for IRKnowledge:
Users that are interested in IRKnowledge are comparing it to the libraries listed below
- MalRecon - Basic Malware Reconnaissance and Analysis Tool☆26Updated 7 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆42Updated 4 years ago
- GUI Tool to generate threat intelligence information in various formats☆43Updated 7 years ago
- Digital Forensics and Incident Response Wiki☆40Updated 10 years ago
- Fast incident overview☆39Updated 7 years ago
- Carve Windows Prefetch files from arbitrary binary data☆14Updated 7 years ago
- Threat Intel and Incident Reponse☆10Updated 6 years ago
- Here comes the paintrain!☆11Updated 8 years ago
- This is a copy of the Registry Decoder Live repository from Google Code☆9Updated 9 years ago
- Server for receiving autorun data from the clients☆13Updated 7 years ago
- My personal Automated Malware Analysis Sandboxes and Services☆24Updated 7 years ago
- A Single Library Parser to extract meta information,static analysis and detect macros within the files.☆1Updated 6 years ago
- Plugins to add funtionality to ProcDOT. http://www.procdot.com☆23Updated last year
- Endpoint monitoring stack.☆18Updated 9 years ago
- Basic file metadata gathering script☆21Updated 3 years ago
- Tools to work with vulnerability standards.☆19Updated 10 years ago
- Set of utilities for getting information about Windows Events☆15Updated 6 years ago
- Force-Directed Graph Generator for Volatility Ouputs☆26Updated 5 years ago
- Extracts indicators of compromise (IOCs), including domain names, IPv4 addresses, email addresses, and hashes, from text.☆13Updated 7 years ago
- Working through Practical Malware Analysis from No Starch Press☆13Updated 7 years ago
- Invoke remote powershell scripts in memory of compromised hosts.☆10Updated 10 years ago
- Tool for analysts to perform simultaneous lookups (IP, Domain, URL, MD5) against multiple data sources☆29Updated 8 years ago
- IDS Utility Belt For Automating/Testing Various Things☆30Updated 4 years ago
- Virustotal Data to Timesketch☆17Updated 5 years ago
- Python parser for Red Canary's Atomic Red Team Yamls☆27Updated 5 years ago
- Discover potential timestamps within the Windows Registry☆18Updated 10 years ago
- ☆16Updated 10 years ago
- Multiple rules for yara-project for detect compiler/packer/protector☆33Updated 5 years ago
- API Tools☆27Updated 8 years ago
- Metasploit modules, powershell scripts and custom exploit to perform local privilege escalation on windows systems.☆10Updated 7 years ago