The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the host system. Created for incident response Team.
☆32May 21, 2026Updated 2 months ago
Alternatives and similar repositories for DFIR_Linux_Collector
Users that are interested in DFIR_Linux_Collector are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Bring Your Own Mitre Att&ck © Matrix !☆13Oct 19, 2023Updated 2 years ago
- DFIRLab / Plateforme d'investigation numérique☆15Jul 6, 2021Updated 5 years ago
- Scripts to integrate DFIR-IRIS, MISP and TimeSketch☆37Feb 2, 2022Updated 4 years ago
- Knowing which rule should trigger according to the redcannary test☆11Nov 23, 2024Updated last year
- ☆18Jan 18, 2022Updated 4 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Generate malware traces for detection tests☆16Updated this week
- ☆70May 3, 2021Updated 5 years ago
- ☆54May 14, 2024Updated 2 years ago
- Volatility3 Linux profiles☆84Jun 29, 2026Updated last month
- Construct triage artifact based on rules☆16Jun 18, 2026Updated last month
- Python client for DFIR-IRIS☆29Aug 19, 2024Updated last year
- Volatility Symbol Generator for Linux Kernels☆37Nov 15, 2023Updated 2 years ago
- Jupyter Notebooks for Digital Forensics & Incident Response☆10Nov 23, 2021Updated 4 years ago
- Tool to extract indicators of compromise from security reports in PDF,HTML,Web,Text format☆10Nov 6, 2017Updated 8 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Apr 22, 2021Updated 5 years ago
- Incident Response - Fast suspicious file finder☆260Jan 24, 2026Updated 6 months ago
- Volatility, on Docker 🐳☆41Nov 20, 2025Updated 8 months ago
- A DFIR Incident Response AI bot using local Ollama LLM to derrive automated findings from logs☆16Jan 17, 2026Updated 6 months ago
- simple webapp for converting sigma rules into siem queries using the pySigma library☆50Sep 1, 2023Updated 2 years ago
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆17Oct 28, 2023Updated 2 years ago
- Learn about a network from a pcap file or reading from an interface☆29Apr 6, 2024Updated 2 years ago
- MBC v2.x expressed in STIX 2.1 JSON☆17Oct 3, 2023Updated 2 years ago
- Live forensic artifacts collector☆177Jul 5, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Validates Sigma rules using the JSON schema☆24Apr 24, 2026Updated 3 months ago
- Simple Script to Help You Find All Files Has Been Modified, Accessed, and Created In A Range Time.☆27Dec 1, 2022Updated 3 years ago
- Tool to build and simulate Dofus Arena teams☆17Feb 18, 2026Updated 5 months ago
- Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles☆194Jul 17, 2026Updated 3 weeks ago
- YAFRA is a semi-automated framework for analyzing and representing reports about IT Security incidents.☆27Dec 14, 2021Updated 4 years ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆21Jul 1, 2023Updated 3 years ago
- Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or event…☆76Jul 13, 2021Updated 5 years ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆841Updated this week
- Algorithme d'apprentissage statistique permettant de créer un modèle sur les lignes de commandes des évènements "Création de Processus", …☆84Feb 21, 2024Updated 2 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Check Sigma rules for easy-to-bypass whitelists to make them more robust (https://github.com/SigmaHQ/sigma)☆16Feb 1, 2021Updated 5 years ago
- $MFT directory tree reconstruction & FILE record info☆331Oct 7, 2024Updated last year
- Forensics artefact collection tool for systems running Microsoft Windows☆445Jul 29, 2026Updated last week
- Import specific data sources into the Sigma generic and open signature format.☆78May 6, 2022Updated 4 years ago
- Load MISP events into memcached for log enrichment using logstash☆12Jul 10, 2020Updated 6 years ago
- Web Application for domain name monitoring / alerting☆66Aug 1, 2024Updated 2 years ago
- Netwitness Maltego integration Project☆18May 9, 2017Updated 9 years ago