Binary analysis and management framework
created at Nov. 9, 2013, 6:24 p.m.
(DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR) teams quickly identify suspicious hosts on which to focus their response.
created at May 1, 2018, 10:11 p.m.
Windows Events Attack Samples
created at March 15, 2019, 8:45 a.m.
Investigate malicious Windows logon by visualizing and analyzing Windows event log
created at Nov. 24, 2017, 6:07 a.m.
Please no pull requests for this repository. Thanks!
created at May 8, 2015, 11:21 a.m.
A forensic evidence collection & analysis toolkit for OS X
created at Aug. 4, 2014, 6:25 p.m.
A toolset to make a system look as if it was the victim of an APT attack
created at Feb. 3, 2018, 2:19 p.m.
StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define.
created at Jan. 22, 2017, 1:10 a.m.
Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com
created at Oct. 13, 2014, 9:26 p.m.
Virtual Machine for Adversary Emulation and Threat Hunting
created at March 14, 2018, 7:31 p.m.
Incident Response Forensic Framework
created at July 6, 2016, 11:02 a.m.
LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures from Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it to produce memory captures that are more forensically sound than those of other tools designed for Linux memory acquisition.
created at Sept. 23, 2014, 4:23 p.m.
This is the development tree. Production downloads are at:
created at April 3, 2012, 4:36 a.m.
An information security preparedness tool to do adversarial simulation.
created at Nov. 1, 2017, 9:24 p.m.