LogonTracer by JPCERTCC

Investigate malicious Windows logon by visualizing and analyzing Windows event log

updated at Nov. 16, 2024, 7:41 a.m.

Python

136 +0

2,735 +6

443 +0

GitHub
Hoarder by muteb

This script is made to collect the most valiable artifacts for foreniscs or incident reponse investigation rather than imaging the whole har drive.

updated at Nov. 16, 2024, 7:32 a.m.

Python

10 +0

193 +1

19 +0

GitHub
VolDiff by aim4r

VolDiff: Malware Memory Footprint Analysis based on Volatility

updated at Nov. 16, 2024, 7:18 a.m.

Python

28 +0

193 +1

50 +0

GitHub
orochi by LDO-CERT

The Volatility Collaborative GUI

updated at Nov. 16, 2024, 7:18 a.m.

JavaScript

11 +0

225 +2

19 +0

GitHub
inVtero.net by ShaneK2

inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques

updated at Nov. 16, 2024, 7:14 a.m.

C#

30 +0

279 +1

57 +0

GitHub
fibratus by rabbitstack

Adversary tradecraft detection, protection, and hunting

updated at Nov. 16, 2024, 6:59 a.m.

Go

70 +0

2,210 +0

190 +0

GitHub
grr by google

GRR Rapid Response: remote live forensics for incident response

updated at Nov. 16, 2024, 4:08 a.m.

Python

316 +1

4,783 +9

763 +2

GitHub
catalyst by SecurityBrewery

⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident response processes

updated at Nov. 16, 2024, 3:51 a.m.

Vue

7 +0

350 +4

37 +0

GitHub
Fenrir by Neo23x0

Simple Bash IOC Scanner

updated at Nov. 16, 2024, 2:17 a.m.

Shell

41 +0

697 +3

103 +0

GitHub
Loki by Neo23x0

Loki - Simple IOC and YARA Scanner

updated at Nov. 16, 2024, 2:16 a.m.

Python

184 +0

3,402 +7

583 +0

GitHub
mac_apt by ydkhatri

macOS (& ios) Artifact Parsing Tool

updated at Nov. 15, 2024, 11:47 p.m.

Python

44 +0

782 +2

102 +2

GitHub
matano by matanolabs

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

updated at Nov. 15, 2024, 9:32 p.m.

Rust

22 +0

1,472 +8

100 +0

GitHub
Meerkat by TonyPhipps

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

updated at Nov. 15, 2024, 5:06 p.m.

PowerShell

31 +0

435 +0

82 +0

GitHub
Aurora-Incident-Response by cyb3rfox

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

updated at Nov. 15, 2024, 4:46 p.m.

JavaScript

42 +0

766 +1

81 +0

GitHub
timesketch by google

Collaborative forensic timeline analysis

updated at Nov. 15, 2024, 1:11 p.m.

Python

137 +0

2,614 +6

589 +0

GitHub
plaso by log2timeline

Super timeline all the things

updated at Nov. 15, 2024, 12:45 p.m.

Python

94 +1

1,734 +2

352 +1

GitHub
dissect by fox-it

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (part of NCC Group).

updated at Nov. 15, 2024, 10:36 a.m.

Unknown languages

22 +0

924 +3

65 +1

GitHub
dftimewolf by log2timeline

A framework for orchestrating forensic collection, processing and data export

updated at Nov. 15, 2024, 4:23 a.m.

Python

27 +0

296 -1

72 +0

GitHub
metta by uber-common

An information security preparedness tool to do adversarial simulation.

updated at Nov. 14, 2024, 1:53 p.m.

Python

75 +0

1,101 +3

151 +0

GitHub
flightsim by alphasoc

A utility to safely generate malicious network traffic patterns and evaluate controls.

updated at Nov. 14, 2024, 10:47 a.m.

Go

35 +0

1,260 +3

132 +0

GitHub