iris-web by dfir-iris

Collaborative Incident Response platform

updated at Nov. 17, 2024, 3:38 a.m.

JavaScript

28 +0

1,079 +5

184 +2

GitHub
EVTX-ATTACK-SAMPLES by sbousseaden

Windows Events Attack Samples

updated at Nov. 17, 2024, 1:41 a.m.

HTML

143 -1

2,248 +3

398 +0

GitHub
hayabusa by Yamato-Security

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

updated at Nov. 17, 2024, 1:36 a.m.

Rust

42 +1

2,305 +15

203 +0

GitHub
radare2 by radareorg

UNIX-like reverse engineering framework and command-line toolset

updated at Nov. 17, 2024, 1:24 a.m.

C

488 +1

20,710 +33

3,006 +3

GitHub
bulk_extractor by simsong

This is the development tree. Production downloads are at:

updated at Nov. 17, 2024, 12:02 a.m.

C++

76 +0

1,115 +3

187 +0

GitHub
CimSweep by mattifestation

CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.

updated at Nov. 16, 2024, 11:05 p.m.

PowerShell

75 +1

650 +5

148 +0

GitHub
hindsight by obsidianforensics

Web browser forensics for Google Chrome/Chromium

updated at Nov. 16, 2024, 10:13 p.m.

Python

67 +0

1,087 +5

142 +1

GitHub
artifactcollector by forensicanalysis

🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system

updated at Nov. 16, 2024, 10:08 p.m.

Go

8 +0

270 +2

21 +0

GitHub
APTSimulator by NextronSystems

A toolset to make a system look as if it was the victim of an APT attack

updated at Nov. 16, 2024, 9:46 p.m.

Batchfile

122 +0

2,469 +6

428 +0

GitHub
RegRipper3.0 by keydet89

RegRipper3.0

updated at Nov. 16, 2024, 9:26 p.m.

Perl

26 +0

557 +3

126 +3

GitHub
dfir-orc by DFIR-ORC

Forensics artefact collection tool for systems running Microsoft Windows

updated at Nov. 16, 2024, 8:31 p.m.

C++

26 -1

387 +1

42 +0

GitHub
capa by mandiant

The FLARE team's open-source tool to identify capabilities in executable files.

updated at Nov. 16, 2024, 7:08 p.m.

Python

82 +0

4,875 +18

560 +2

GitHub
LiME by 504ensicsLabs

LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures from Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it to produce memory captures that are more forensically sound than those of other tools designed for Linux memory acquisition.

updated at Nov. 16, 2024, 6:08 p.m.

C

81 +0

1,724 +0

340 +1

GitHub
fleet by fleetdm

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)

updated at Nov. 16, 2024, 5:22 p.m.

Go

36 +2

3,119 +12

431 +4

GitHub
MalConfScan by JPCERTCC

Volatility plugin for extracts configuration data of known malware

updated at Nov. 16, 2024, 4:34 p.m.

Python

36 +0

485 +2

67 +0

GitHub
sigma by SigmaHQ

Main Sigma Rule Repository

updated at Nov. 16, 2024, 4:32 p.m.

Python

346 +1

8,369 +32

2,198 -2

GitHub
ThreatHunter-Playbook by OTRF

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

updated at Nov. 16, 2024, 3:22 p.m.

Python

372 +0

4,023 +5

807 -1

GitHub
zentral by zentralopensource

Zentral is a high-visibility platform for controlling Apple endpoints in enterprises. It brings great observability to IT and makes tracking & reporting compliance much less manual.

updated at Nov. 16, 2024, 2:52 p.m.

Python

32 +0

752 +1

82 +0

GitHub
stenographer by google

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com

updated at Nov. 16, 2024, 8:38 a.m.

Go

101 +0

1,790 +2

238 +0

GitHub
security-onion by Security-Onion-Solutions

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

updated at Nov. 16, 2024, 8:33 a.m.

Unknown languages

301 +0

3,076 +3

522 +1

GitHub