Statistics for topic dfir
RepositoryStats tracks 584,797 Github repositories, of these 181 are tagged with the dfir topic. The most common primary language for repositories using this topic is Python (64). Other languages include: PowerShell (26)
Stargazers over time for topic dfir
Most starred repositories for topic dfir (view more)
Trending repositories for topic dfir (view more)
A curated list of tools for incident response
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Rapidly Search and Hunt through Windows Forensic Artefacts
Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in this exciting journey and add your expertise to our collective eff...
Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in this exciting journey and add your expertise to our collective eff...
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
A curated list of tools for incident response
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
⭐️ A curated list of awesome forensic analysis tools and resources
Rapidly Search and Hunt through Windows Forensic Artefacts
This is a repository dedicated to the DFIR journey. Contains notes, reflections and links to tools.
Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in this exciting journey and add your expertise to our collective eff...
TRACE is a digital forensic analysis tool that provides a user-friendly interface for investigating disk images.
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.
MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
Rapidly Search and Hunt through Windows Forensic Artefacts
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
A curated list of tools for incident response
⭐️ A curated list of awesome forensic analysis tools and resources
LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. This project gathers procedural examples from public reports of ...
This is a repository dedicated to the DFIR journey. Contains notes, reflections and links to tools.
MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
TRACE is a digital forensic analysis tool that provides a user-friendly interface for investigating disk images.
yara detection rules for hunting with the threathunting-keywords project
MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. This project gathers procedural examples from public reports of ...
A curated list of tools for incident response
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
⭐️ A curated list of awesome forensic analysis tools and resources
A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts
A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.
Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indicator matches.
PowerShell script designed to help Incident Responders collect forensic evidence from local and remote Windows devices.