artifacts-kb by ForensicArtifacts

Digital Forensics Artifacts Knowledge Base

updated at Nov. 2, 2024, 12:41 a.m.

Python

7 +0

75 +0

16 +0

GitHub
ir-rescue by diogo-fernan

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

updated at Nov. 1, 2024, 5:08 p.m.

Batchfile

44 +0

465 +0

95 +0

GitHub
falcon-orchestrator by CrowdStrike

CrowdStrike Falcon Orchestrator provides automated workflow and response capabilities

updated at Oct. 30, 2024, 3:26 p.m.

JavaScript

35 +0

186 +0

54 +0

GitHub
MFT_Browser by kacos2000

$MFT directory tree reconstruction & FILE record info

updated at Oct. 29, 2024, 9:41 p.m.

PowerShell

13 +0

292 +0

32 +0

GitHub
SPECTR3 by alpine-sec

Forensic tool for acquisition, triage and analysis of remote block devices via iSCSI protocol.

updated at Oct. 25, 2024, 7:56 a.m.

C#

5 +0

37 +0

3 +0

GitHub
viper by viper-framework

Binary analysis and management framework

updated at Oct. 25, 2024, 1:49 a.m.

Python

148 +0

1,539 +0

350 +0

GitHub
threat_note by DefensePointSecurity

DPS' Lightweight Investigation Notebook

updated at Oct. 24, 2024, 2:56 a.m.

HTML

57 +0

423 +0

97 +0

GitHub
nightHawkResponse by biggiesmallsAG

Incident Response Forensic Framework

updated at Oct. 23, 2024, 6:23 p.m.

Go

82 +0

598 +0

125 +0

GitHub
domfind by diogo-fernan

A Python DNS crawler to find identical domain names under different TLDs.

updated at Oct. 22, 2024, 7:12 p.m.

Python

4 +0

24 +0

3 +0

GitHub
gsvsoc_cirt-playbook-battle-cards by guardsight

Cyber Incident Response Team Playbook Battle Cards

updated at Oct. 21, 2024, 2:10 p.m.

Unknown languages

17 +0

360 +0

67 +1

GitHub
SysmonSearch by JPCERTCC

Investigate suspicious activity by visualizing Sysmon's event log

updated at Oct. 21, 2024, 10:37 a.m.

JavaScript

43 +0

417 +0

58 +0

GitHub
mastiff by KoreLogicSecurity

Malware static analysis framework

updated at Oct. 21, 2024, 10:37 a.m.

Python

18 +0

174 +0

40 +0

GitHub
rastrea2r by rastrea2r

Collecting & Hunting for IOCs with gusto and style

updated at Oct. 21, 2024, 7:56 a.m.

Python

17 +0

238 +0

53 +0

GitHub
spyre by spyre-project

simple YARA-based IOC scanner

updated at Oct. 19, 2024, 2:56 p.m.

Go

12 +0

164 +0

27 +0

GitHub
dfirtrack by dfirtrack

DFIRTrack - The Incident Response Tracking Application

updated at Oct. 17, 2024, 7:23 a.m.

Python

25 +0

482 +0

75 +0

GitHub
traceroute-circl by CIRCL

Traceroute improved wrapper for CSIRT and CERT operators

updated at Oct. 9, 2024, 6:38 a.m.

Perl

16 +0

37 +0

9 +0

GitHub
morgue by etsy

post mortem tracker

updated at Oct. 7, 2024, 11:23 p.m.

PHP

74 +0

1,017 +0

133 +0

GitHub
lorg by jensvoid

Apache Logfile Security Analyzer

updated at Oct. 6, 2024, 11:03 p.m.

HTML

42 +0

209 +0

50 +0

GitHub
visualize_logs by keithjjones

A Python library and command line tools to provide interactive log visualization.

updated at Oct. 3, 2024, 5:12 a.m.

HTML

15 +0

137 +0

30 +0

GitHub
cuckoo-modified-api by keithjjones

A Python library to interface with a cuckoo-modified instance

updated at Oct. 3, 2024, 5:12 a.m.

Python

6 +0

21 +0

7 +0

GitHub