w8mej / IRKnowledge
A curated list of tools for incident response
☆29Updated last year
Alternatives and similar repositories for IRKnowledge
Users that are interested in IRKnowledge are comparing it to the libraries listed below
Sorting:
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆42Updated 4 years ago
- An active domain name query tool to help keep track of domain name movements...☆15Updated 4 years ago
- My personal Automated Malware Analysis Sandboxes and Services☆24Updated 8 years ago
- This is a copy of the Registry Decoder Live repository from Google Code☆9Updated 9 years ago
- Tools to work with vulnerability standards.☆19Updated 11 years ago
- Server for receiving autorun data from the clients☆13Updated 7 years ago
- MalRecon - Basic Malware Reconnaissance and Analysis Tool☆26Updated 7 years ago
- Collection of single use scripts I worte for windows forensics☆27Updated 13 years ago
- Recon-ng modules that won't get accepted into the main distribution because of 3rd party dependencies.☆18Updated 11 years ago
- IDS Utility Belt For Automating/Testing Various Things☆30Updated 4 years ago
- Why hunt when you can seine?☆21Updated 10 years ago
- Multiple rules for yara-project for detect compiler/packer/protector☆33Updated 5 years ago
- Threat Intel and Incident Reponse☆10Updated 6 years ago
- Here comes the paintrain!☆11Updated 8 years ago
- Working through Practical Malware Analysis from No Starch Press☆13Updated 8 years ago
- Awesome little automater☆17Updated 12 years ago
- Extracts indicators of compromise (IOCs), including domain names, IPv4 addresses, email addresses, and hashes, from text.☆13Updated 7 years ago
- Invoke remote powershell scripts in memory of compromised hosts.☆11Updated 10 years ago
- The repository contains IOCs in CSV format for APT, Cyber Crimes, Malware and Trojan and whatever I found as part of hunting and research☆12Updated 7 years ago
- Carves EXEs from given data files, using intelligent carving based upon PE headers☆38Updated 8 years ago
- Honeypot for router backdoor (TCP 32764)☆18Updated 11 years ago
- Artefacts from various retefe campaigns☆10Updated 6 years ago
- Plugins to add funtionality to ProcDOT. http://www.procdot.com☆23Updated last year
- Tool for automation of GUI-based testing.☆15Updated 10 years ago
- Duo MFA auditing tool to test users' likelihood of approving unexpected push notifications☆13Updated 7 years ago
- Discover potential timestamps within the Windows Registry☆18Updated 11 years ago
- Yet-Another-BlueTeam-Repo-YABTR. A Repo for a collection of FREE Blue team tools for both windows and Linux.. Not vendor buy to defend pr…☆2Updated 5 years ago
- Digital Forensics and Incident Response Wiki☆40Updated 10 years ago
- Basic file metadata gathering script☆21Updated last month
- Linux and Windows Hardening Points☆12Updated 7 years ago