stringsifter by mandiant

A machine learning tool that ranks strings based on their relevance for malware analysis.

updated at May 13, 2024, 6:36 a.m.

Python

30 +0

649 +0

123 +0

GitHub
fileintel by keithjjones

A modular Python application to pull intelligence about malicious files

updated at May 14, 2024, 12:11 p.m.

Python

17 +0

114 +0

25 +0

GitHub
mutablesecurity by MutableSecurity

CLI program for automating the setup, configuration, and use of cybersecurity solutions

updated at May 14, 2024, 9:23 p.m.

Python

1 +0

42 +0

7 +0

GitHub
Fastir_Collector_Linux by SekoiaLab

None

updated at May 14, 2024, 9:31 p.m.

Python

23 +0

166 +0

43 +0

GitHub
imagemounter by ralphje

Command line utility and Python package to ease the (un)mounting of forensic disk images

updated at May 15, 2024, 10:31 a.m.

Python

13 +0

112 +0

36 +0

GitHub
appcompatprocessor by mbevilacqua

"Evolving AppCompat/AmCache data analysis beyond grep"

updated at May 16, 2024, 1:39 p.m.

Python

17 +0

190 +0

26 +0

GitHub
dfirtrack by dfirtrack

DFIRTrack - The Incident Response Tracking Application

updated at May 17, 2024, 8:40 a.m.

Python

25 +0

466 +0

75 +0

GitHub
mac_apt by ydkhatri

macOS (& ios) Artifact Parsing Tool

updated at May 17, 2024, 12:14 p.m.

Python

44 +0

719 +0

99 +0

GitHub
streamalert by airbnb

StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define.

updated at May 17, 2024, 9:17 p.m.

Python

101 +0

2,825 +0

334 +0

GitHub
artifacts-kb by ForensicArtifacts

Digital Forensics Artifacts Knowledge Base

updated at May 18, 2024, 5:38 a.m.

Python

8 +0

68 +0

15 +0

GitHub
cuckoo-modified by spender-sandbox

Modified edition of cuckoo

updated at May 18, 2024, 9:51 a.m.

Python

72 +0

389 +0

178 +0

GitHub
hindsight by obsidianforensics

Web browser forensics for Google Chrome/Chromium

updated at May 20, 2024, 1:19 a.m.

Python

67 +0

1,027 +1

134 +0

GitHub
APT-Hunter by ahmedkhlief

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

updated at May 20, 2024, 8:26 a.m.

Python

47 +0

1,158 +1

229 +0

GitHub
osxcollector by Yelp

A forensic evidence collection & analysis toolkit for OS X

updated at May 20, 2024, 6:15 p.m.

Python

125 +0

1,861 +1

240 +0

GitHub
viper by viper-framework

Binary analysis and management framework

updated at May 22, 2024, 6:44 a.m.

Python

148 +1

1,534 +1

352 +0

GitHub
munin by Neo23x0

Online hash checker for Virustotal and other services

updated at May 22, 2024, 7:34 a.m.

Python

42 +0

800 +2

147 +0

GitHub
MalConfScan by JPCERTCC

Volatility plugin for extracts configuration data of known malware

updated at May 23, 2024, 7:16 a.m.

Python

36 +0

472 +1

68 +0

GitHub
MozDef by mozilla

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

updated at May 23, 2024, 9:48 a.m.

Python

149 +0

2,175 +1

329 +0

GitHub
DumpsterFire by TryCatchHCF

"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.

updated at May 23, 2024, 11:19 a.m.

Python

50 +0

970 +3

148 +0

GitHub
acquire by fox-it

acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container.

updated at May 23, 2024, 1:43 p.m.

Python

12 +0

77 +0

17 -1

GitHub