atomic-red-team by redcanaryco

Small and highly portable detection tests based on MITRE's ATT&CK.

updated at May 25, 2024, 5:37 p.m.

C

347 +0

9,169 +33

2,682 +4

GitHub
HELK by Cyb3rWard0g

The Hunting ELK

updated at May 25, 2024, 4:18 p.m.

Jupyter Notebook

215 -1

3,710 +5

673 +0

GitHub
rizin by rizinorg

UNIX-like reverse engineering framework and command-line toolset.

updated at May 25, 2024, 4:16 p.m.

C

45 +0

2,474 +7

327 -3

GitHub
awesome-event-ids by stuhli

Collection of Event ID ressources useful for Digital Forensics and Incident Response

updated at May 25, 2024, 3:37 p.m.

Unknown languages

24 +0

549 +2

82 +0

GitHub
zentral by zentralopensource

Zentral is a high-visibility platform for controlling Apple endpoints in enterprises. It brings great observability to IT and makes tracking & reporting compliance much less manual.

updated at May 25, 2024, 3:27 p.m.

Python

31 +0

722 +0

83 +0

GitHub
chainsaw by WithSecureLabs

Rapidly Search and Hunt through Windows Forensic Artefacts

updated at May 25, 2024, 2:50 p.m.

Rust

50 +0

2,574 +6

230 +2

GitHub
sigma by SigmaHQ

Main Sigma Rule Repository

updated at May 25, 2024, 2:43 p.m.

Python

328 +1

7,723 +23

2,103 +0

GitHub
Fenrir by Neo23x0

Simple Bash IOC Scanner

updated at May 25, 2024, 2:38 p.m.

Shell

39 +0

664 +1

103 +0

GitHub
Loki by Neo23x0

Loki - Simple IOC and YARA Scanner

updated at May 25, 2024, 2:35 p.m.

Python

187 +0

3,254 +0

574 -1

GitHub
sysmon-config by SwiftOnSecurity

Sysmon configuration file template with default high-quality event tracing

updated at May 25, 2024, 12:07 p.m.

Unknown languages

357 +0

4,601 +7

1,674 +3

GitHub
iris-web by dfir-iris

Collaborative Incident Response platform

updated at May 25, 2024, 11:26 a.m.

JavaScript

26 +0

953 +8

146 +2

GitHub
velociraptor by Velocidex

Digging Deeper....

updated at May 25, 2024, 8:20 a.m.

Go

72 +2

2,716 +13

454 +2

GitHub
CAPEv2 by kevoreilly

Malware Configuration And Payload Extraction

updated at May 25, 2024, 7:43 a.m.

Python

65 +1

1,707 +5

381 +0

GitHub
caldera by mitre

Automated Adversary Emulation Platform

updated at May 25, 2024, 3:12 a.m.

Python

166 +0

5,241 +17

1,018 +3

GitHub
bulk_extractor by simsong

This is the development tree. Production downloads are at:

updated at May 25, 2024, 12:15 a.m.

C++

74 +0

1,021 +2

181 +0

GitHub
stenographer by google

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com

updated at May 24, 2024, 10:23 p.m.

Go

104 +0

1,789 +1

233 +1

GitHub
artifacts by ForensicArtifacts

Digital Forensics artifact repository

updated at May 24, 2024, 7:53 p.m.

Python

73 +0

994 +3

203 -1

GitHub
metta by uber-common

An information security preparedness tool to do adversarial simulation.

updated at May 24, 2024, 6:38 p.m.

Python

74 +0

1,077 +3

150 -1

GitHub
flightsim by alphasoc

A utility to safely generate malicious network traffic patterns and evaluate controls.

updated at May 24, 2024, 6:08 p.m.

Go

35 +0

1,195 +3

128 +0

GitHub
sysmon-modular by olafhartong

A repository of sysmon configuration modules

updated at May 24, 2024, 5:46 p.m.

PowerShell

164 +0

2,504 +2

568 +0

GitHub