Sysmon configuration file template with default high-quality event tracing
created at Feb. 1, 2017, 6:49 p.m.
Digital Forensics artifact repository
created at Oct. 31, 2014, 7:13 p.m.
A repository of sysmon configuration modules
created at Jan. 13, 2018, 9:20 p.m.
Windows Events Attack Samples
created at March 15, 2019, 8:45 a.m.
Digital Forensics Artifacts Knowledge Base
created at Jan. 17, 2018, 7:31 p.m.
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
created at March 28, 2017, 3:07 a.m.
A framework for orchestrating forensic collection, processing and data export
created at July 29, 2016, 1:54 p.m.
Please no pull requests for this repository. Thanks!
created at May 8, 2015, 11:21 a.m.
$MFT directory tree reconstruction & FILE record info
created at Dec. 26, 2020, 2:28 a.m.
Collection of Event ID ressources useful for Digital Forensics and Incident Response
created at Sept. 22, 2021, 3:36 p.m.
⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident response processes
created at Dec. 12, 2021, 11:37 p.m.