The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the host system. Created for incident response Team.
☆32Mar 9, 2022Updated 3 years ago
Alternatives and similar repositories for DFIR_Linux_Collector
Users that are interested in DFIR_Linux_Collector are comparing it to the libraries listed below
Sorting:
- Bring Your Own Mitre Att&ck © Matrix !☆13Oct 19, 2023Updated 2 years ago
- Scripts to integrate DFIR-IRIS, MISP and TimeSketch☆35Feb 2, 2022Updated 4 years ago
- Sigma rules converted for direct use with Zircolite☆14Updated this week
- DFIRLab / Plateforme d'investigation numérique☆15Jul 6, 2021Updated 4 years ago
- ☆18Jan 18, 2022Updated 4 years ago
- Knowing which rule should trigger according to the redcannary test☆11Nov 23, 2024Updated last year
- Tool to extract indicators of compromise from security reports in PDF,HTML,Web,Text format☆10Nov 6, 2017Updated 8 years ago
- Learn about a network from a pcap file or reading from an interface☆29Apr 6, 2024Updated last year
- Python client for DFIR-IRIS☆25Aug 19, 2024Updated last year
- Volatility3 Linux profiles☆75Dec 8, 2025Updated 2 months ago
- MBC v2.x expressed in STIX 2.1 JSON☆16Oct 3, 2023Updated 2 years ago
- ☆54May 14, 2024Updated last year
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆32Nov 23, 2025Updated 3 months ago
- Check Sigma rules for easy-to-bypass whitelists to make them more robust (https://github.com/SigmaHQ/sigma)☆15Feb 1, 2021Updated 5 years ago
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆17Oct 28, 2023Updated 2 years ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆20Jul 1, 2023Updated 2 years ago
- Volatility Symbol Generator for Linux Kernels☆37Nov 15, 2023Updated 2 years ago
- Volatility, on Docker 🐳☆41Nov 20, 2025Updated 3 months ago
- ☆69May 3, 2021Updated 4 years ago
- Live forensic artifacts collector☆172Jul 5, 2024Updated last year
- Validates Sigma rules using the JSON schema☆22Mar 18, 2024Updated last year
- petit "playbook" qui pourrait servir de base à une réponse à incident lors d'une attaque de type ransomware☆21Aug 30, 2022Updated 3 years ago
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,249Updated this week
- Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or event…☆77Jul 13, 2021Updated 4 years ago
- Algorithme d'apprentissage statistique permettant de créer un modèle sur les lignes de commandes des évènements "Création de Processus", …☆83Feb 21, 2024Updated 2 years ago
- Incident Response - Fast suspicious file finder☆249Jan 24, 2026Updated last month
- ☆42Sep 16, 2022Updated 3 years ago
- All the useful tools interesting to be used☆24Sep 20, 2022Updated 3 years ago
- Forensics artefact collection tool for systems running Microsoft Windows☆431Mar 26, 2025Updated 11 months ago
- ☆25Jul 23, 2024Updated last year
- Cyber Threat Intelligence☆78Dec 7, 2025Updated 2 months ago
- A pcap capture analysis helper☆25Aug 30, 2023Updated 2 years ago
- An opensource sigma conversion tool built using pysigma☆160Feb 9, 2026Updated 3 weeks ago
- Artifact collection tool for *nix systems☆212Mar 20, 2024Updated last year
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆785Feb 22, 2026Updated last week
- simple webapp for converting sigma rules into siem queries using the pySigma library☆52Sep 1, 2023Updated 2 years ago
- YAFRA is a semi-automated framework for analyzing and representing reports about IT Security incidents.☆27Dec 14, 2021Updated 4 years ago
- Simple Script to Help You Find All Files Has Been Modified, Accessed, and Created In A Range Time.☆27Dec 1, 2022Updated 3 years ago
- FFXI Gearswap Lua for the impaired☆10Feb 2, 2026Updated last month