Statistics for topic dfir
RepositoryStats tracks 595,856 Github repositories, of these 182 are tagged with the dfir topic. The most common primary language for repositories using this topic is Python (64). Other languages include: PowerShell (26)
Stargazers over time for topic dfir
Most starred repositories for topic dfir (view more)
Trending repositories for topic dfir (view more)
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
A curated list of tools for incident response
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.
A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.
A curated list of tools for incident response. With repository stars⭐ and forks🍴
A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
A curated list of tools for incident response
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
This is a repository dedicated to the DFIR journey. Contains notes, reflections and links to tools.
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
A curated list of tools for incident response
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.
TRACE is a digital forensic analysis tool that provides a user-friendly interface for investigating disk images.
LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. This project gathers procedural examples from public reports of ...
A curated list of tools for incident response
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
⭐️ A curated list of awesome forensic analysis tools and resources
A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts
MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
PowerShell script designed to help Incident Responders collect forensic evidence from local and remote Windows devices.
This is a repository dedicated to the DFIR journey. Contains notes, reflections and links to tools.