Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders
created at June 9, 2020, 12:12 p.m.
A framework for orchestrating forensic collection, processing and data export
created at July 29, 2016, 1:54 p.m.
Cyber Incident Response Team Playbook Battle Cards
created at Oct. 27, 2019, 4:28 a.m.
Volatility plugin for extracts configuration data of known malware
created at April 22, 2019, 12:23 a.m.
(DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR) teams quickly identify suspicious hosts on which to focus their response.
created at May 1, 2018, 10:11 p.m.
VolatilityBot – An automated memory analyzer for malware samples and memory dumps
created at Feb. 4, 2015, 3:13 p.m.
Investigate suspicious activity by visualizing Sysmon's event log
created at July 31, 2018, 11:25 p.m.
inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques
created at April 29, 2011, 4:37 a.m.
CrowdStrike Falcon Orchestrator provides automated workflow and response capabilities
created at April 22, 2016, 1:25 a.m.
A modular Python application to collect intelligence for malicious hosts.
created at Aug. 22, 2016, 8:25 p.m.
Remote Memory Acquisition Tool
created at Aug. 9, 2016, 5:39 p.m.